Answer the question
In order to leave comments, you need to log in
How to protect the site and server?
Good afternoon, dear participants.
Yesterday I noticed referrals from a strange site - acunetix-referrer.com. I read that this is a website vulnerability scanner.
This service created links like
sitename/?wvstest=javascript:domxssExecutionSink(1,%22%27\%22%3E%3Cxsstag%3E()locxss%22)
PDOException: SQLSTATE[23000]: Integrity CONSTRAINT violation: 1062 Duplicate entry 'node-110-0-0-und' FOR KEY 'PRIMARY': INSERT INTO {field_data_field_fivestar} (entity_type, entity_id, revision_id, bundle, delta, LANGUAGE, field_fivestar_rating, field_fivestar_target) VALUES (:db_insert_placeholder_0, :db_insert_placeholder_1, :db_insert_placeholder_2, :db_insert_placeholder_3, :db_insert_placeholder_4, :db_insert_placeholder_5, :db_insert_placeholder_6, :db_insert_placeholder_7); Array ( [:db_insert_placeholder_0] => node [:db_insert_placeholder_1] => 110 [:db_insert_placeholder_2] => 110 [:db_insert_placeholder_3] => service [:db_insert_placeholder_4] => 0 [:db_insert_placeholder_5] => und [:db_insert_placeholder_6] => 20 [:db_insert_placeholder_7] => ) в функции field_sql_storage_field_storage_write() (строка 514 в файле /var/www/drupal/modules/FIELD/modules/field_sql_storage/field_sql_storage.module).
PDOException: SQLSTATE[HY000]: General error: 1366 Incorrect INTEGER VALUE: '-' FOR COLUMN 'field_fivestar_rating' at ROW 1: INSERT INTO {field_data_field_fivestar} (entity_type, entity_id, revision_id, bundle, delta, LANGUAGE, field_fivestar_rating, field_fivestar_target) VALUES (:db_insert_placeholder_0, :db_insert_placeholder_1, :db_insert_placeholder_2, :db_insert_placeholder_3, :db_insert_placeholder_4, :db_insert_placeholder_5, :db_insert_placeholder_6, :db_insert_placeholder_7); Array ( [:db_insert_placeholder_0] => node [:db_insert_placeholder_1] => 110 [:db_insert_placeholder_2] => 110 [:db_insert_placeholder_3] => service [:db_insert_placeholder_4] => 0 [:db_insert_placeholder_5] => und [:db_insert_placeholder_6] => - [:db_insert_placeholder_7] => ) в функции field_sql_storage_field_storage_write() (строка 514 в файле /var/www/drupal/modules/FIELD/modules/field_sql_storage/field_sql_storage.module).
Answer the question
In order to leave comments, you need to log in
What to do
Fix your govnokoda
whether you need to block? There is no point
1. Not worth it. The fact that you have closed yourself from scanners does not save you from vulnerabilities. The principle of Security through obscurity comes out, and it should be avoided in such matters.
2. It's worth it, but it's not a panacea. Here are the setup instructions.
3. I would check myself with these scanners to see a problem report! And hand tools, of course. Things to try: Acunetix , METASCAN , Detectify . And don't forget to update your CMS!
1. Yes, via WAF.
2. naxsi is more relevant.
3. WAF simply reduces the likelihood, but does not eliminate it.
It is best to limit the rights so that hacking one of the sites does not affect others.
Acunetix is, of course, a security scanner, but it has nothing to do with this situation. It's just that the enemies are trying to mask their malicious activities. Puma Thailand is right - you need to patch vulnerabilities (or at least update Drupal).
1. Not worth it. We scanned the site for holes for free. Yes, with a rather harsh reminder of what happens in such cases. And at the same time with a reminder about backups :)
3. I would start by updating the engine, then analyzing my code and making changes...
3) Set up rules in iptables (if on Linux), install and configure a firewall (if on Windows)
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question