March 8th, 2007, 01:53 AM
Weird Entries in my logs
I log the contents of user searches into a database table and found some weird entries in it this morning. The script only searches specified tables i.e I haven't indexed my entire site with a crawler script or anything so they couldn't find the terms below.
The searches were:
and several others. Each request was 5 or 6 seconds apart and tried a couple of different search options from my dropdown list of search types.
I Googled a few of them and saw they were Window's DLL's or something?
Any idea what this was?
March 8th, 2007, 02:32 PM
What are the users supposed to search for? I wouldn't worry too much about it. There aren't any really weird things in there like a' OR 1=1; SELECT * FROM users; ?
Experience is something you don't get until just after you need it.
March 8th, 2007, 09:48 PM
It's a music site, so definitely not the terms I found :-)
What are the users supposed to search for?
All my input is filtered for attacks like you mentioned.
March 9th, 2007, 09:56 AM
Maybe its users being idiots and searching the wrong site? Either:
1) They think you have those files
2) They are bored and want to see if you have those files
All of the above perhaps.
But I'm with SirDice on this one, searching for silly files no problem. Putting SQL type nonsense or web headers etc, different matter.
If the world doesn't stop annoying me I will name my kids ";DROP DATABASE;" and get revenge.
By Irongeek in forum Web Security
Last Post: March 2nd, 2006, 04:36 PM
By st34ever in forum Web Security
Last Post: January 27th, 2005, 01:10 PM
By rpgraff in forum Spyware / Adware
Last Post: August 24th, 2004, 08:01 AM
By Tiger Shark in forum The Security Tutorials Forum
Last Post: March 4th, 2004, 04:00 PM
By qod in forum The Security Tutorials Forum
Last Post: February 27th, 2004, 02:03 AM