Hack attack targetting SQL SERVER sites

Discussion in 'C#' started by mazzetta, Jun 15, 2008.

  1. #1
    If u run an SQL Server 2000 DB, you may be targeted by a new botnet hack (banner82) thru SQL injection.
    Two fast step to avoid being hacked are:
    - Set permission denied on the system tables: sysobjects and syscolumns of your db. In enterprise managers, click on the tables open "authorization" and deny averything for everyone. This should be enough to block the attack.
    - Catch the queystring in each page and parse it for terms like "EXEC" or "DECLARE" (you may want to add more like "<script" and so on)m if u find those terms, redirect to nowhere.

    Hope this helps to secure your sites before they get attacked. Run daily backups of the db!

    Is easy to clean db from the attached string both in var and text fields, the problem is that the attack appends himself after truncating text fields to 4000 char, so the only viable option if u have longer texts is to restore a db backup.
     
    mazzetta, Jun 15, 2008 IP
  2. itcn

    itcn Well-Known Member

    Messages:
    795
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    118
    #2
    Do you have a CERT advisory on this new attack?
     
    itcn, Jun 16, 2008 IP
  3. centsi

    centsi Active Member

    Messages:
    83
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    56
    #3
    Any update on this?
     
    centsi, Jun 17, 2008 IP
  4. shaileshk

    shaileshk Well-Known Member

    Messages:
    455
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    108