Simple Machines Community Forum

Archived Boards and Threads... => Archived Boards => SMF Feedback and Discussion => Topic started by: jhb8426 on July 03, 2012, 05:48:23 PM

Title: Is this a breakin attempt?
Post by: jhb8426 on July 03, 2012, 05:48:23 PM
Recently I see these entries in the ban log, usually from banned accounts trying to login again. These will be in the stream. The bolded entries are what I am questioning.

58.215.64.147    Guest    Sorry Guest, you are banned from using this forum!
spammer-lifecaf
?action=profile;u=14716\" and \"x\"=\"y    Today at 12:22:01 PM
58.215.64.147    Guest    Sorry Guest, you are banned from using this forum!
spammer-lifecaf
?action=profile;u=14716\" and \"x\"=\"x    Today at 12:21:59 PM
58.215.64.147    Guest    Sorry Guest, you are banned from using this forum!
spammer-lifecaf
?action=profile;u=14716\' and \'x\'=\'y    Today at 12:21:57 PM
58.215.64.147    Guest    Sorry Guest, you are banned from using this forum!
spammer-lifecaf
?action=profile;u=14716\' and \'x\'=\'x    Today at 12:21:55 PM

I often see the profile queries, but what does the \' and \'x\'=\'x  etc mean/attempt?
Title: Re: Is this a breakin attempt?
Post by: Arantor on July 03, 2012, 06:04:24 PM
Yes, it's a break-in attempt - failed (though it would have failed without the ban)

I would try and explain what they're attempting to do but it's complicated - if you want to read up on it, it's what's called an SQL injection. Though there are two separate protections involved for ?action=profile so really don't worry about it.
Title: Re: Is this a breakin attempt?
Post by: jhb8426 on July 03, 2012, 06:33:03 PM
Thanks much.