Site hacked and IPS didn't detect a thing

hi
one of our websites was hacked, the attacker used weakness in the scripting, what he did was added to the address "http://www.xxx.com/details.asp?id=xxx+update+textnews+..." and by this he changed the main page.
My question is why the IPS did not detect it ? isn'this some known form of SQL injection ?
is there some good explanation about these types of attacks and what should be done to further prevent this type of attacks
Thanks a lot

I assume the application is custom, not purchased "off the shelf"? It looks like your custom application is vulnerability to some form of URL tampering, but without more details it's hard to be sure. IDS is a signature based technology and as such doesn't do such a good job of detecting flaws in custom applications. If you allow HTTPS, it has no chance. There is something called an application firewall that is generally more effective for securing custom applications.
"isn'this some known form of SQL injection"
based on what you provided, I would say no. It looks like simple URL tampering.
"is there some good explanation about these types of attacks and what should be done to further prevent this type of attacks"
see [variable manipulation]:
http://www.owasp.org/index.php/OWASP_AppSec_FAQ
fix your application. knowing how to do that is beyond the scope of this forum. hopefully the owasp guide and site can help you.

Similar Messages

  • Security issues using Open Realty and DW (any sites hacked?)...

    I am doing a real estate site and woud prefer to stick with DW and integrate the Open Realty plugin rather than jump in to Joomla for ease of manipulating the overall design. Have any of you ever had any sites hacked using OR? I know you have to use pconnect to use OR; does this increase MySQL vulnerability? I am using GoDaddy and am not sure if they even allow pconnect on their Linux/Apache servers...

    A Trojan Horse almost always results from someone visiting a web site and/or receiving email and in the process inadvertently downloading malicious software. Therefore, it is the *computer user* that literally invites this malware into their computer. This malware did not get into the PCs on your network because someone on the internet got past your network's "firewall" ie the Airport Base Station.
    What someone needs to do is to educate these PC users on your network on the basics of "safe computing", and to install and maintain software on their PCs to guard against and detect this type of malware at the moment it gains entry to the PC. What you do not need to do is expend effort beefing up the security of your network's connection to the internet.

  • Can we assign 2 IPs for a SCCM 2012 primary site server and use 1 IP for communicating with its 2 DPs and 2nd one for communicating with its upper hierarchy CAS which is in a different .Domain

    Hi,
    Can we assign 2 IPs for a SCCM 2012 primary site server and use 1 Ip for communicating with its 2 DPs and 2nd one for communicating with its upper hierarchy CAS . ?
    Scenario: We are building 1 SCCM 2012 primary site and 2 DPs in one domain . In future this will attach to a CAS server which is in different domain. Can we assign  2 IPs in Primary site server , one IP will use to communicate with its 2 DPs and second
    IP for communicating with the CAS server which is in a different domain.? 
    Details: 
    1)Server : Windows 2012 R2 Std , VM environment .2) SCCM : SCCM 2012 R2 .3)SQL: SQL 2012 Std
    Thanks
    Rajesh Vasudevan

    First, it's not possible. You cannot attach a primary site to an existing CAS.
    Primary sites in 2012 are *not* the same as primary sites in 2007 and a CAS is 2012 is completely different from a central primary site in 2007.
    CASes cannot manage clients. Also, primary sites are *not* used for delegation in 2012. As Torsten points out, multiple primary sites are used for scale-out (in terms of client count) only. Placing primary sites for different organizational units provides
    no functional differences but does add complexity, latency, and additional failure points.
    Thus, as the others have pointed out, your premise for doing this is completely incorrect. What are your actual business goals?
    As for the IP Addressing, that depends upon your networking infrastructure. There is no way to configure ConfigMgr to use different interfaces for different types of traffic. You could potentially manipulate the routing tables in Windows but that's asking
    for trouble IMO.
    Jason | http://blog.configmgrftw.com | @jasonsandys

  • My ipod didn't turn on and it can't detect in itunes..

    Today,i sync new books with itunes and move it to ipod then put ipod side and doing my work then i took it and try to wake it up but it didn't respond and also it didn't detect in itunes...it's battery is also full.So that's not promblem..i tried everything lyk get out of DFU mode..but it can't really help me...plzzz help me ....

    Connect the iPod to the computer and restore via iTunes. If necessary, place the iPod inRecovery Mode to allow the restore.

  • How can I remove viruses off my computer? I have mac OS X, but I clicked on a website on google and it didn't open. Instead the security program popped up and said that my computer is at risk of a crash and has detected several viruses!?!?! AAAAHHH!?!?!

    How can I remove viruses off my computer? I have mac OS X, but I clicked on a website on google and it didn't open. Instead the security program popped up and said that my computer is at risk of a crash and has detected several viruses!?!?! AAAAHHH!?!?!

    MnM
    It's probably the MacDefender scareware trojan horse. If you have this here is how to remove it.
    1. Open Activity Monitor look for MacDefender process double click on it and hit quit or force quit.
    2. Go to System Preferences, Go to accounts, Go to login items look for anything related to MacDefender hightlight it by clcking on it once. Then hit the minus sign to remove it.
    3. Go to applications folder and drag MacDefender to the trash.
    4. Open finder and do a search for Macdefender and remove anything you see related to MacDefender.
    5. Open Spotlight (the little magnyfing glass in the menubar far right corner) and do a search for MacDefender.
    6. Restart your computer and empty trash.
    7. If you feel you need to have virus protection for your Mac use ClamXav. It's the recommended AV program for MacOSX. Hope this helps.
    Joseph

  • Window has detected and IPS Address Conflict

         To Whom this my concern,  I keep getting this message, which, I had mention in the subject line.  I have reset my wifi box and the box, that Charter gave me quit a few times. But, this message keeps on coming up, for some odd reason or another. 
         I was just wondering.  I had a Hp Lap Top 2000, that some one had stoolen off me, quit a few months, ago. I reported it to the police station and HP and they said that they could not do anything about it. Because, I absolutely lost my serial number, that I had written down.
        But, I used the same email addresses and Passwords on both computes. So, I was just a wondering if the person could be useing the lap top, that I had gotten stoolen from me and this is the way, this is why this message keeps popping up on my computer.
        Oh, I even called up Charter and mention it to them and they absolutely could not figure out what is going on either. So, I just thought, that I would text it on the internet.  To see if any one absolutely knew what was going on.
    Well, if you want to get in touch with me.  My email address it [Personal Information Removed]  or
    [Personal Information Removed].
    If you could help me out. I would appreciate it and awful lots.
                                                                                                                                                        Yours Sincerely,
                                                                                                                                                         Mr. Rockie A. Bates

    Hi @Rockiebates1949 ,
    Thank you for visiting the HP Support Forums and Welcome. I have looked into your issue about your Window has detected and IPS Address Conflict on your Home Network. This error message indicates that another computer on the network is using the same IP address that your computer is using. Each computer on a network must have a unique IP address. To fix this problem, run the Network troubleshooter.
    I hope this helps.
    Thanks.
    Please click “Accept as Solution ” if you feel my post solved your issue, it will help others find the solution.
    Click the “Kudos, Thumbs Up" on the bottom to say “Thanks” for helping!

  • The Links-hacked and Elinks thread

    I have just installed this Links-hacked and so far I'm loving it. I have the best of both worlds: the lightness and speed of a text browser, plus the ability to use graphics.
    Now my only problem is that I can't find my way around to configure it. For example, I can't find a keyboard shortcut to open a new tab, or a way to have numbered links.
    So far I have to say it's not as good as Elinks, but it's surely the best option. I don't think I would be able to completely switch to a text-only browser, and I hope the graphics Elinks version is released as soon as possible.
    I think Elinks is the best text-browser I have seen, perhaps the best web browser.
    Anyway, this is the PKGBUILD I have put together from the comments on AUR:
    pkgname=links-hacked
    pkgver=030709
    pkgrel=1
    pkgdesc="An enhanced version of links with support for tabs"
    pkgurl="http://xray.sai.msu.ru/~karpov/links-hacked/"
    arch=('i686')
    # Web-site down indefinitely
    url="http://xray.sai.msu.ru/~karpov/links-hacked/"
    # Source URLs point to the PKGBUILD-maker's webspace. No longer available from the maintainer's site.
    source=(http://xray.sai.msu.ru/~karpov/links-hacked/downloads/$pkgname-$pkgver.tgz http://xray.sai.msu.ru/~karpov/links-hacked/downloads/links-fonts-new.tgz)
    depends=('openssl' 'x-server' 'gpm' 'bzip2' 'libtiff')
    md5sums=(74fb710ecfa89aceb51211f7dce24ab0 1176ee9132c9df8c1ec955e28bff6f5b)
    conflicts=(links)
    build() {
    cd $startdir/src/$pkgname-$pkgver/
    mv ../font ./
    ./autogen.sh
    ./configure --prefix=/usr --enable-ssl --enable-javascript --enable-graphics
    sed -i "s|load_failure:|load_failure:; {}|g" options.c
    sed -i "s|already_drawn:|already_drawn:; {}|g" options_manager.c
    sed -i "s|tabs_end:|tabs_end:; {}|g" view_gr.c
    sed -ri "s|^.*prune_font_cache.*$||" links.h
    make || return 1
    make prefix=$startdir/pkg/usr install
    So, if you have any suggestion or personal configuration to suggest, please do.
    So far what I have succesfully configured are the fonts. You can add more fonts by simply specifying your font path in the font manager, then in the User Interface menu, you can write manually the name of the font you want. A bit unpractical, but it works.
    Last edited by finferflu (2008-01-01 21:23:02)

    Thanks for finding that out, finferflu. I too had stumbled on some pages that didn't work and do now with ipv6.
    edit: I presume you mean the elinks.conf options
    set connection.try_ipv4 = 1
    set connection.try_ipv6 = 0
    But the second option gives an error with --disable-ipv6, making it still not work.
    edit2:
    The man page says:
    connection.try_ipv4 [0|1] (default: 1)
    Whether to try to connect to a host over IPv4. Note that if connection.try_ipv6 is enabled too, it takes prece-
    dence. And better do not touch this at all unless you are sure what are you doing. Note that you can also force a
    given protocol to be used on a per-connection basis by using an URL in the style of i.e. http4://elinks.or.cz/.
    connection.try_ipv6 [0|1] (default: 1)
    Whether to try to connect to a host over IPv6. Note that you can also force a given protocol to be used on a
    per-connection basis by using an URL in the style of i.e. http6://elinks.or.cz/.
    However going to http4://yubnub.org with --disable-ipv6 doesn't work.
    Last edited by Gilneas (2008-01-02 20:10:54)

  • Hey there! So I plugged in my ipod to my computer and it didn't show up where it normally does. I need to update my song list. How can I make it appear? It doesn't come up in Iphoto. A few days ago my sispluggeditintoanothercomputerbutidon'tknowwhatshedid

    Hey there! So I plugged in my ipod to my computer and it didn't show up where it normally does. I need to update my song list. How can I make it appear? It doesn't come up in iphoto either. A few days ago my sis plugged it into another computer but I don't know if she synched it to the other computer, and frankly, she won't remember. I have tried updating itunes, charging the ipod, restarting the ipod/computer, and the rest of what the apple site said to do. Ps I have the latest ipod touch
    I need help stat! Please help!

    I'd say your sister messed up and your iPod is toasted.
    Think about it...  She plugged it in to another computer, she doesn't remember what she did (yeah, right), and now your iPod is not being recognized by your computer... 
    Also take into consideration how old is your sister, and how much does she know about electronics?

  • My entire phone got hacked and now I believe there is a cloned phone number who is texting my contacts....very bad things and I don't know what to do....get a new phone?  New number?

    Within the last few months I have gotten several snap shots of conversations from friends that showed it was my phone number but the conversation was not from me.  It was someone using my information but texting frieda, family, and some co workers very obscene things.  But the person was using completely juvenile context and I don't do that at all with my texts.  The worst part was it began becoming such a huge issue when the cloned number or whatever was texting guys stuff and I wasn't the actual person texting.  I got no responses to my phone but I had some very confused friends and even at one point my boyfriend got texts from my number when I was literally sitting next to him and my phone was on the coffee table.  Anyone have any ideas on what I need to do.  I have reset my phone, deleted everything off of it, reset passwords, I don't use location services but I am still having people getting crude messages.  It's to the point now that my very own friends don't talk to me through text or my personal email because they don't know if it is truly me.  Please help!

    Your phone is not hacked however your sim card probably IS cloned.
    YOU need to contact your Mobile Network and local police right NOW !

  • Firefox will not fully load and run anymore just out of the blue when I click to run it it just sits and does not respond I have totally uninstalled and reinstalled this many times and it still does the same thing why would it stop working?

    When I booted my computer up from cold and click firefox to run it sat there and tryed to load instead it sits there and does the nor responding thing. I have totally uninstalled the program a few times and re installed a new download and the same thing happen. I can not run firefox any longer and i have run it everyday for a very long time. This seems to be the only program with an issue.

    None of the stuff in " http://kb.mozillazine.org/Locked_or_damaged_places.sqlite " helps. I have tried and tried and I have even wipe the computer clean still didn't help. I got the same problem as he/she has got in the first posted. Can add some web pages but not all the web pages I want.. I should have never updated to 3.6.13... That's when it all started for me, from that version..... Now Version 3.6.14 is out, I was hoping the version 3.6.14 might would fix the problem wrong again....
    Funny thing is i can not even Bookmark Firefox.com!!!!!...lol
    So any ideas on how to fix it other than the link giving would help.
    Thanks.

  • My windows and iTunes is not detecting to my iPod.

    I'm having trouble loading my iPod onto my computer and iTunes. I reinstalled and reset several times, but it still didn't work. When I installed my iTunes with the CD, it didn't detect my iPod. When I plugged in my iPod, the wizard window popped up, and I tried to install it that way. Then while it's installing, a "Hardwar Installation" window comes up. It says, "The software you are installing for this hardware: USB Mass Storage Device has not passed Windows Logo testing to verify its compatibility with Windows XP", and I should STOP INSTALLATION. So, I do and the wizard says that I cannot install this hardware. I don't know what to do. Anybody have any ideas?

    Hi, I'm having a similar problem, except I didn't get a "Windows Logo Test" thing. Anyway, if it asks you that again, just say yes. The iPod should do no harm to your computer, seeing how you've connected it before. Some people think the problem w/ this is that a windows update blocks the iPod from working.

  • HT5278 iOS 5.1.1 Software Update - I have just attempted to install this update on my 3gs and at the final stage was presented with an error message of 1602 and now my phone has frozen. Yes I have tried all the usual ways to resolve this and it didn't wor

    iOS 5.1.1 Software Update - just tried to update and it didn't work! Got to the final stages and was presented with error 1602! My screen now has the frozen image of the itunes logo and usb thing. Happened once before - funnily enough when doing an update back in November - I had to visit an Apple store to have the phone restored. Would appreciate any advice as I would like to avoid another trip to the apple store.

    found the real problem.
    In my laptop where it couldn't detect the iphone and ipad, this folder is missing:
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\Drivers
    The ipad was wrongly using a microsoft driver.
    I found the correct drivers in:
    C:\Windows\System32\DriverStore\FileRepository\usbaapl64.inf_amd64_neutral_c111a aecb61e9a2b
    Copy the contents to
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\Drivers
    After that, I had to update the driver for Ipad in device manager.
    Ipad was found under: "Removable Devices", as a storage device.
    Once that is fixed, itunes can detect ipad, and I can restore it.
    Apple should really look into ensuring that folder doesn't go missing during itunes update process.

  • This morning Find My Phone alert went off on all my devices connected to my Apple ID at the same time, is this a bug or should I be worried that my id is hacked? I didn't have Find My Phone app installed on many of these devices. Please advice. Thanks

    This morning Find My Phone alert went off on all my devices connected to my Apple ID at the same time, is this a bug or should I be worried that my id is hacked? I didn't have Find My Phone app installed on many of these devices. Please advice. Thanks in advance.

    If you have enabled Find My iPhone/iPad on your devices, any one with access to your Apple ID and Password can Play Sound on your devices.
    Tap to enlarge image.

  • I am trying to access iTune store but keep on getting message "cannot access iTune store" i have reset my password several times and it didn't help. My apple ID has been confirmed as correct. what can I do next?

    Hi all
    i am trying to access iTune store but keep on getting message "cannot access iTune store" i have reset my password several times and it didn’t help. My apple ID has been confirmed as correct. what can I do next?

    I am having the same issue!  I see several people are having this problem, and I see there is no solution from Apple!  Why is it I only see problems on this site and never any solutions?

  • What can I do if my account is hacked and apps are purchased?

    Hi, I rarely use my itunes account and I just logged in to purchase a song and noticed that my itunes account balance is next to nothing, When I looked up my previous purchases it appears someone had used my account and purchasd apps in a foreign language. I don't own any other apple devices other than my ipod nano. So, It's pretty clear that I didn't purchase those items. What can I do to get my credit back? Thanks

    Sweet, I just got hacked and found out that I have to take it up with my credit card company!  Way to go Apple!  

Maybe you are looking for