Results 1 to 3 of 3
  1. #1
    Join Date
    Sep 2007
    Posts
    1

    Unanswered: My site got hacked!

    Hi folks,

    I have a site built in classic asp that pulls from a MSSQL db and sometime in the last week it was hacked by the notorious turkish hackers . I restored the db, luckily, I had just backed it up.

    The hosting company said that it was most likely the ' or 'x'='x hack and said that it was entirely up to me to fix the problem. I have no ideas. Any help?

    Thanks in advance.

    bardman6

  2. #2
    Join Date
    Jan 2007
    Location
    UK
    Posts
    11,434
    Provided Answers: 10
    Quote Originally Posted by bardman6
    t was most likely the ' or 'x'='x hack
    That is a common technique called SQL injection, there is a heap of information out there if you go Google. I would advise that you disallow the use of apostrophes, semi-colons etc in any of your input areas (textboxes and the like).

    Aren't you glad you had that backup, eh!
    Make sure you keep that up - frequent backups are key!
    George
    Home | Blog

  3. #3
    Join Date
    Mar 2003
    Location
    The Bottom of The Barrel
    Posts
    6,102
    Provided Answers: 1
    Prepared statements FTW.
    oh yeah... documentation... I have heard of that.

    *** What Do You Want In The MS Access Forum? ***

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •