Announcement

Collapse
No announcement yet.

Dodgy contact submissions

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Dodgy contact submissions

    Last week we got hundreds of emails from three of our websites contact us forms that are all very similar. I presume this is someone trying to do something they shouldn't be doing and break into our site.
    Is this something we should be worying about or something we can do anything about?

    Here is an example...

    Subscribe to Seriously SIlver Newsletter. It was submitted by
    1 declare @q varchar(8000) select @q = 0x57414954464F522044454C4159202730303A30303A313527 exec(@q) -- (somebody@mailer.nu) on Monday, May 24, 2010 at 20:40:01
    ---------------------------------------------------------------------------


    pagename: John

    anchor: 1

    url: http://

    description: 1

    ourlink: http://

    ---------------------------------------------------------------------------
    Unusual Silver Jewellery
    Giftmill - Unusual Gifts
    Crystal Healing Jewellery
    Steampunk Jewellery

    #2
    We had dozen of these also in the last week usually in batches of 10-20 over a 15 minutes timespan.
    The subject heading was usually something like:
    1) declare @q varchar(8000) select @q = 0x57414954464F522044454C4159202730303A30303A313527 exec(@q) --
    and message content:
    Name:John
    Email Address:somebody@mailer.nu
    Message:
    1
    Darren Guppy
    Golf Tee Warehouse
    Golf Tees and Golf Accessories.

    Comment


      #3
      I had quite a few of these over a couple of days at the same time. From what I discovered it was an attempt to exploit SQL databases.


      Bikster
      SellerDeck Designs and Responsive Themes

      Comment

      Working...
      X