Is this a breakin attempt?

Started by jhb8426, July 03, 2012, 05:48:23 PM

Previous topic - Next topic

jhb8426

Recently I see these entries in the ban log, usually from banned accounts trying to login again. These will be in the stream. The bolded entries are what I am questioning.

58.215.64.147    Guest    Sorry Guest, you are banned from using this forum!
spammer-lifecaf
?action=profile;u=14716\" and \"x\"=\"y    Today at 12:22:01 PM
58.215.64.147    Guest    Sorry Guest, you are banned from using this forum!
spammer-lifecaf
?action=profile;u=14716\" and \"x\"=\"x    Today at 12:21:59 PM
58.215.64.147    Guest    Sorry Guest, you are banned from using this forum!
spammer-lifecaf
?action=profile;u=14716\' and \'x\'=\'y    Today at 12:21:57 PM
58.215.64.147    Guest    Sorry Guest, you are banned from using this forum!
spammer-lifecaf
?action=profile;u=14716\' and \'x\'=\'x    Today at 12:21:55 PM

I often see the profile queries, but what does the \' and \'x\'=\'x  etc mean/attempt?

Arantor

Yes, it's a break-in attempt - failed (though it would have failed without the ban)

I would try and explain what they're attempting to do but it's complicated - if you want to read up on it, it's what's called an SQL injection. Though there are two separate protections involved for ?action=profile so really don't worry about it.
Holder of controversial views, all of which my own.


jhb8426


Advertisement: