Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 will upgrading solve my SQL injection problem?
 New Topic  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

alltp
Starting Member

36 Posts

Posted - 31 July 2007 :  14:31:57  Show Profile  Visit alltp's Homepage
Our website www.tabletpcbuzz.com has been hit numerous times with a script injection into the SQL database. I purchased the website about 2 months ago and didn't realize it was an old version (3.4.03). Just upgraded it today to the latest and greatest.

Am I safe?

John Hill
www.alltp.com
www.tabletpcbuzz.com
www.tabletpcbuzz.com/3dbuzz

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 31 July 2007 :  18:59:27  Show Profile  Send ruirib a Yahoo! Message
Upgrading should indeed fix the sql injection issues. Just applying the security fixes posted since the version was released would fix it, but if you have the opportunity to upgrade, you should do it.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

alltp
Starting Member

36 Posts

Posted - 31 July 2007 :  20:40:57  Show Profile  Visit alltp's Homepage
thanks - it has been a real drag. I upgrade to .06 and am looking forward to everything running smoothly.

When I ran the "Check Installation" there were some errors, but at the end it said "database upgraded successfully" and the version in the admin section says "3.4.06"

Anything else I need to check?

John Hill
www.alltp.com
www.tabletpcbuzz.com
www.tabletpcbuzz.com/3dbuzz
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 31 July 2007 :  23:10:47  Show Profile  Send ruirib a Yahoo! Message
You will have to apply this security fix: http://forum.snitz.com/forum/topic.asp?TOPIC_ID=64248

There are also a couple bugs that you need to fix:

http://forum.snitz.com/forum/topic.asp?TOPIC_ID=62792
http://forum.snitz.com/forum/topic.asp?TOPIC_ID=62798&SearchTerms=pop_mail


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

Shaggy
Support Moderator

Ireland
6780 Posts

Posted - 01 August 2007 :  04:22:03  Show Profile
Just to be certain sure that this isn't a new exploit, how did they execute the injection? Also, what were the errors you received when running setup.asp, just in case they're something you should look at?


Search is your friend
“I was having a mildly paranoid day, mostly due to the
fact that the mad priest lady from over the river had
taken to nailing weasels to my front door again.”
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.35 seconds. Powered By: Snitz Forums 2000 Version 3.4.07