Lost Password?

Go Back   CodeCall Programming Forum > Web Development Forum > Database & Database Programming

Database & Database Programming MySQL, Oracle, SQL, PL/SQL, ABAP, Smart Forms, and other databases and languages. A database is an organized body of related information used in many websites (including CC).

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 03-12-2008, 08:51 PM
egon egon is offline
Newbie
 
Join Date: Oct 2006
Location: Iowa
Posts: 13
Rep Power: 0
egon is on a distinguished road
Send a message via AIM to egon
Default Site getting hacked? Heavy SQL use

Hey all, I'm not good with this stuff. My DB usage has been ridiculous lately, and my friend told me I'm getting hacked. Checking apache logs gave me this the first time it happened:

---------------------------------------------------
[27/Feb/2008:12:19:11 -0800] "GET /comments/feed/ HTTP/1.1" 500 391 "-" "FeedBurner/1.0 (http://www.FeedBurner.com)" "-"
---------------------------------------------------

For whatever reason this specific request ran for 5 minutes and 40 second. While running, it issued the following mysql query:

---------------------------------------------------
SELECT option_value FROM wp_options WHERE option_name = 'siteurl'.
---------------------------------------------------

This query was issued repeatedly and rapidly for the duration of the 5 minutes and 40 seconds.

Next, which was just about an hour ago:

---------------------------------------------------
Mar 12 13:21:20 10.2.0.57 query_logger.pl[3241]: INFO: 1371783 "db22***" "***database-name***" IDX_YES 1 SELECT bb4b264131236a7f922e526e281b7db5 -- SELECT option_value FROM wp_options WHERE option_name = 'siteurl'
---------------------------------------------------

The loop was occurring 500 times per second for at least 5 minutes. The asterisks are the database name.

I'm using an outdated version of Wordpress but can't upgrade until my designer sends my new theme.

My host is busting my balls over this...can someone please help?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Sponsored Links
  #2 (permalink)  
Old 03-12-2008, 09:09 PM
TkTech TkTech is offline
CrazyOne
 
Join Date: Jun 2006
Posts: 718
Last Blog:
Having trouble with yo...
Rep Power: 50
TkTech is on a distinguished road
Send a message via MSN to TkTech
Default Re: Site getting hacked? Heavy SQL use

I would like to test this myself, would you mind sending me the URL of your site, in PM if you wish.

FeedBurner is NOT a malicious site, however someone could be using its nature of pinging a recently added feed to DDoS your site. It may be best to use .htaccess to block out the site for awhile.
__________________
CodeCall Blog | CodeCall Wiki | Shareware | Linux Forum
Chat with other CodeCall members on IRC; connect to irc.codecall.net and join #codecall
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Top 10 Ways To Promote Your Web Site ravs2k6 Marketing 30 02-02-2008 04:20 AM
Best program for SQL database manipulation Rhadamanthys Database & Database Programming 3 07-02-2007 02:32 PM
Online RPG For Sale - Predicted PR 5 phb50530 Site Reviews 10 01-10-2007 05:59 AM
Oracle has more Flaws than MS SQL? Jordan Database & Database Programming 9 12-05-2006 09:39 AM


All times are GMT -5. The time now is 03:15 PM.

Contest Stats

John ........ 87.50000
dargueta ........ 75.00000
Xav ........ 50.00000
MeTh0Dz ........ 20.00000
gaylo565 ........ 18.00000
Johnnyboy ........ 3.00000

Contest Rules

Ads