ExpressionEngine CMS
Open, Free, Amazing

Thread

This is an archived forum and the content is probably no longer relevant, but is provided here for posterity.

The active forums are here.

Problem: Injection Database

April 16, 2008 5:50am

Subscribe [7]
  • #16 / Apr 21, 2008 10:17am

    George Ornbo

    272 posts

    I’d second that. That kind of response is not really acceptable for a professional hosting company, especially when the matter relates to security.

  • #17 / Apr 21, 2008 12:58pm

    Cocoaholic

    445 posts

    I put the 1.6.3 version now.

    Seems you have access to your database again?

  • #18 / Apr 22, 2008 8:50am

    sauvesourissss

    36 posts

    Yes, I have access to my database now.

    Derek, I sent you by email informations that 1&1;sent me.

    Thank you very much

  • #19 / Apr 22, 2008 10:32am

    Derek Allard

    3168 posts

    Hi Savuvesourissss,

    The email you sent me was simply 8 queries that were generated when a report on “slow sql” was run.  There is nothing I see in this that would in indicate an attack was attempted.  At worst, this indicates that if you aren’t using trackbacks you should disable them.  There is nothing about using parameters on the end of a URL that is in itself risky (make a google search and then look at the address bar). 

    So essentially, I see nothing here to indicate that you were attacked.  If 1&1;can provide any further information I assure you I’d be very receptive.  I’d also add that there is a tremendous difference between being attacked, and being attacked successfully.  It would not be unreasonable for any host to say that you were the target of an attack, the fact is that by having a publicly accessible site we are all targets - however ExpressionEngine goes to great lengths to protect you.  Consider this, if 8 buglers come up to my house’s front door, but can’t get through the lock and give up and walk away, has my house been robbed? 

    Please let us know if any further information surfaces.  For now I’m going to mark this thread as resolved, but if you should learn anything else I’ll re-open it immediately.

.(JavaScript must be enabled to view this email address)

ExpressionEngine News!

#eecms, #events, #releases