<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-2672754150485551359.post6336527887627733229..comments</id><updated>2009-04-16T18:06:18.102-04:00</updated><title type='text'>Comments on The Security Shoggoth: Another Odd SQL Injection Attack</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://secshoggoth.blogspot.com/feeds/6336527887627733229/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6336527887627733229/comments/default'/><link rel='alternate' type='text/html' href='http://secshoggoth.blogspot.com/2009/03/another-odd-sql-injection-attack.html'/><author><name>Security Shoggoth</name><uri>http://www.blogger.com/profile/15411793726236555303</uri><email>securityshoggoth@gmail.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2672754150485551359.post-5340997910064346916</id><published>2009-04-16T18:06:00.000-04:00</published><updated>2009-04-16T18:06:00.000-04:00</updated><title type='text'>It is just hex represenation of ascii characters.....</title><content type='html'>It is just hex represenation of ascii characters...&lt;br /&gt;&lt;br /&gt;See http://home2.paulschou.net/tools/xlate/ for several conversion options...</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6336527887627733229/comments/default/5340997910064346916'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6336527887627733229/comments/default/5340997910064346916'/><link rel='alternate' type='text/html' href='http://secshoggoth.blogspot.com/2009/03/another-odd-sql-injection-attack.html?showComment=1239919560000#c5340997910064346916' title=''/><author><name>Scott White</name><uri>http://www.blogger.com/profile/04004932007384176459</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://secshoggoth.blogspot.com/2009/03/another-odd-sql-injection-attack.html' ref='tag:blogger.com,1999:blog-2672754150485551359.post-6336527887627733229' source='http://www.blogger.com/feeds/2672754150485551359/posts/default/6336527887627733229' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2672754150485551359.post-5722976788751943583</id><published>2009-04-16T17:34:00.000-04:00</published><updated>2009-04-16T17:34:00.000-04:00</updated><title type='text'>I found your post while attempting to decipher my ...</title><content type='html'>I found your post while attempting to decipher my own attacks and was wondering if you could help me by pointing me towards a converter that can help me decipher the input, for example: 0x27,0x7c,0x5f,0x7c ?&lt;br /&gt;&lt;br /&gt;Any help would be appreciated.&lt;br /&gt;&lt;br /&gt;thanks,&lt;br /&gt;json</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6336527887627733229/comments/default/5722976788751943583'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6336527887627733229/comments/default/5722976788751943583'/><link rel='alternate' type='text/html' href='http://secshoggoth.blogspot.com/2009/03/another-odd-sql-injection-attack.html?showComment=1239917640000#c5722976788751943583' title=''/><author><name>Json</name><uri>http://www.blogger.com/profile/03121259542568255522</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://secshoggoth.blogspot.com/2009/03/another-odd-sql-injection-attack.html' ref='tag:blogger.com,1999:blog-2672754150485551359.post-6336527887627733229' source='http://www.blogger.com/feeds/2672754150485551359/posts/default/6336527887627733229' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2672754150485551359.post-3665264501892712003</id><published>2009-03-16T10:27:00.000-04:00</published><updated>2009-03-16T10:27:00.000-04:00</updated><title type='text'>Scott,  I'm also convinced its from a botnet, if n...</title><content type='html'>Scott,&lt;BR/&gt;&lt;BR/&gt;  I'm also convinced its from a botnet, if nothing else from the sheer number of hits I got.  I didn't post it but we got hit with another.  I attempted to block the hosts via IPTables, but as soon as I'd block 10, 10 more would hit us.  Definitely a botnet.&lt;BR/&gt;&lt;BR/&gt;  It was definitely not successful on our site, but as you can see from various Google searches it did work on others.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6336527887627733229/comments/default/3665264501892712003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6336527887627733229/comments/default/3665264501892712003'/><link rel='alternate' type='text/html' href='http://secshoggoth.blogspot.com/2009/03/another-odd-sql-injection-attack.html?showComment=1237213620000#c3665264501892712003' title=''/><author><name>Security Shoggoth</name><uri>http://www.blogger.com/profile/15411793726236555303</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01799221013624566592'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://secshoggoth.blogspot.com/2009/03/another-odd-sql-injection-attack.html' ref='tag:blogger.com,1999:blog-2672754150485551359.post-6336527887627733229' source='http://www.blogger.com/feeds/2672754150485551359/posts/default/6336527887627733229' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2672754150485551359.post-6641494341255424640</id><published>2009-03-13T13:37:00.000-04:00</published><updated>2009-03-13T13:37:00.000-04:00</updated><title type='text'>Lately there has been some discussion at SecureSta...</title><content type='html'>Lately there has been some discussion at SecureState around these attacks...one approach was using game theory, and less technical analysis...with that being said, I&amp;#39;m fairly confident that we can point this to bot nets, and here is why:&lt;BR/&gt;&lt;BR/&gt;Assume &amp;quot;::xeQ-1-ted::&amp;quot; to be a variation of a handle or screen name...&lt;BR/&gt;&lt;BR/&gt;With that, do some google searches: &lt;BR/&gt;&lt;BR/&gt;http://www.google.com/search?hl=en&amp;amp;safe=off&amp;amp;q=%22xeQted%22&amp;amp;btnG=Search&lt;BR/&gt;&lt;BR/&gt;and &lt;BR/&gt;&lt;BR/&gt;http://www.google.com/search?hl=en&amp;amp;safe=off&amp;amp;rlz=1G1GGLQ_ENUS318&amp;amp;q=%22xeQter%22+-xecuter&amp;amp;btnG=Search&lt;BR/&gt;&lt;BR/&gt;and reveal lots of info like:&lt;BR/&gt;&lt;BR/&gt;http://74.125.95.132/search?q=cache:xWUW4Dg3e6oJ:putih.web.id/forum/viewtopic.php%3Fid%3D483+%22xeQted%22&amp;amp;cd=3&amp;amp;hl=en&amp;amp;ct=clnk&amp;amp;gl=us&lt;BR/&gt;&lt;BR/&gt;http://74.125.95.132/search?q=cache:k3m_IWEtEEAJ:spl0itz.net/board/viewtopic.php%3Ff%3D20%26t%3D341+%22xeQted%22&amp;amp;cd=4&amp;amp;hl=en&amp;amp;ct=clnk&amp;amp;gl=us&lt;BR/&gt;&lt;BR/&gt;http://osdir.com/ml/org.user-groups.linux.twincling/2007-11/msg00051.html&lt;BR/&gt;&lt;BR/&gt;http://www.mail-archive.com/botnets@whitestar.linuxbox.org/msg00800.html&lt;BR/&gt;&lt;BR/&gt;etc.&lt;BR/&gt;&lt;BR/&gt;As far as the attacks being successful or not is a different story, but I think the source may be a little more understood.&lt;BR/&gt;&lt;BR/&gt;Thoughts?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6336527887627733229/comments/default/6641494341255424640'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6336527887627733229/comments/default/6641494341255424640'/><link rel='alternate' type='text/html' href='http://secshoggoth.blogspot.com/2009/03/another-odd-sql-injection-attack.html?showComment=1236965820000#c6641494341255424640' title=''/><author><name>Scott White</name><uri>http://www.blogger.com/profile/04004932007384176459</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://secshoggoth.blogspot.com/2009/03/another-odd-sql-injection-attack.html' ref='tag:blogger.com,1999:blog-2672754150485551359.post-6336527887627733229' source='http://www.blogger.com/feeds/2672754150485551359/posts/default/6336527887627733229' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2672754150485551359.post-7498721540282116025</id><published>2009-03-10T22:04:00.000-04:00</published><updated>2009-03-10T22:04:00.000-04:00</updated><title type='text'>Wow...great point!  In the Google searches I found...</title><content type='html'>Wow...great point!  In the Google searches I found that is exactly what it looks like.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6336527887627733229/comments/default/7498721540282116025'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6336527887627733229/comments/default/7498721540282116025'/><link rel='alternate' type='text/html' href='http://secshoggoth.blogspot.com/2009/03/another-odd-sql-injection-attack.html?showComment=1236737040000#c7498721540282116025' title=''/><author><name>Security Shoggoth</name><uri>http://www.blogger.com/profile/15411793726236555303</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01799221013624566592'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://secshoggoth.blogspot.com/2009/03/another-odd-sql-injection-attack.html' ref='tag:blogger.com,1999:blog-2672754150485551359.post-6336527887627733229' source='http://www.blogger.com/feeds/2672754150485551359/posts/default/6336527887627733229' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2672754150485551359.post-4376657304591460909</id><published>2009-03-10T13:23:00.000-04:00</published><updated>2009-03-10T13:23:00.000-04:00</updated><title type='text'>With that sql, an atacker can easily identify whic...</title><content type='html'>With that sql, an atacker can easily identify which query has been successfully executed (after executing many incrementing the number of parameters), by simply look at the result page and searching for those strange names. They are indeed strange because they need to be easily noticed on that result page.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6336527887627733229/comments/default/4376657304591460909'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6336527887627733229/comments/default/4376657304591460909'/><link rel='alternate' type='text/html' href='http://secshoggoth.blogspot.com/2009/03/another-odd-sql-injection-attack.html?showComment=1236705780000#c4376657304591460909' title=''/><author><name>Jorge Oliveira</name><uri>http://www.blogger.com/profile/13649508673276179519</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://secshoggoth.blogspot.com/2009/03/another-odd-sql-injection-attack.html' ref='tag:blogger.com,1999:blog-2672754150485551359.post-6336527887627733229' source='http://www.blogger.com/feeds/2672754150485551359/posts/default/6336527887627733229' type='text/html'/></entry></feed>