Post by yorkshireboy » Wed Jan 11, 2017 6:37 am

Can anyone help me to understand what the below means - keep getting this error and can't figure out how to fix it

2017-01-07 19:04:44 - PHP Notice: Error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'A=0'' at line 1<br />Error No: 1064<br />SELECT * FROM url_alias WHERE `query` = 'route=0' OR `query` = 'product/product'A=0' in /www/sites/52c/8c8/shop.angeldancewear.co.uk/web/system/library/db/mysqli.php on line 41

site is https://shop.angeldancewear.co.uk/

All help appreaciated

New member

Posts

Joined
Wed Oct 21, 2015 2:10 am
Location - UK

Post by sculptex » Wed Jan 11, 2017 4:37 pm

Remove the apostrophe before A=0

ImageImage


User avatar
Active Member

Posts

Joined
Tue Sep 13, 2011 3:07 am
Location - UK

Post by yorkshireboy » Thu Jan 12, 2017 3:30 am

Thanks @sculptex for the advice - but there is no such entry in my sql.

Is this an SQL injection attack? - and if so, what can be done to stop them?
Thanks

New member

Posts

Joined
Wed Oct 21, 2015 2:10 am
Location - UK

Post by uksitebuilder » Thu Jan 12, 2017 7:13 pm

Looks like this is doing the rounds

I blocked an IP from Aberdeen (Tiscali) today who was also trying that A=0 nonsense

Didn't get any errors in latest version of OC though.

User avatar
Guru Member

Posts

Joined
Thu Jun 09, 2011 11:37 pm
Location - United Kindgom

Post by yorkshireboy » Fri Jan 13, 2017 6:54 am

How did you identify the IP address in order to block it??

New member

Posts

Joined
Wed Oct 21, 2015 2:10 am
Location - UK

Post by uksitebuilder » Fri Jan 13, 2017 3:30 pm

It was in the Customers Online Report list (accessible from the dashboard)

User avatar
Guru Member

Posts

Joined
Thu Jun 09, 2011 11:37 pm
Location - United Kindgom
Who is online

Users browsing this forum: paulfeakins and 57 guests