{"id":853,"date":"2017-10-05T12:06:52","date_gmt":"2017-10-05T00:06:52","guid":{"rendered":"http:\/\/mdickinson.dyndns.org\/php\/wordpress\/?p=853"},"modified":"2017-10-05T12:08:03","modified_gmt":"2017-10-05T00:08:03","slug":"hackers-are-getting-annoying","status":"publish","type":"post","link":"https:\/\/mdickinson.dyndns.org\/php\/wordpress\/?p=853","title":{"rendered":"Hackers are getting annoying"},"content":{"rendered":"<p>My web logs show quite a few sites are now appending the below string to GET query requests that take parameters, the string below has been appended to quite a few requests to my website by multiple ip-addresses.<\/p>\n<pre>\r\nor (1,2)=(select*from(select name_const(CHAR(111,108,111,108,111,115,104,101,114),1),name_const(CHAR(111,108,111,108,111,115,104,101,114),1))a) -- and 1=1'\r\n<\/pre>\n<p>Below are two addresses that were overzealous in doing so and were causing enough log activity for me to take action to block them to make my logs readable again.<\/p>\n<pre>\r\n[root@vosprey2 tmp]# nslookup 184.168.192.72\r\n72.192.168.184.in-addr.arpa name = p3nlwpweb050.shr.prod.phx3.secureserver.net.\r\n\r\nroot@vosprey2 tmp]# nslookup 95.154.220.205\r\n205.220.154.95.in-addr.arpa name = server.ambinet.net.\r\n<\/pre>\n<p>Just shows hackers are still randomly target any internet facing site, even personal ones.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>My web logs show quite a few sites are now appending the below string to GET query requests that take parameters, the string below has been appended to quite a few requests to my website by multiple ip-addresses. or (1,2)=(select*from(select &hellip; <a href=\"https:\/\/mdickinson.dyndns.org\/php\/wordpress\/?p=853\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-853","post","type-post","status-publish","format-standard","hentry","category-my-nux-thoughts-and-notes"],"_links":{"self":[{"href":"https:\/\/mdickinson.dyndns.org\/php\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/853","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mdickinson.dyndns.org\/php\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mdickinson.dyndns.org\/php\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mdickinson.dyndns.org\/php\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/mdickinson.dyndns.org\/php\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=853"}],"version-history":[{"count":3,"href":"https:\/\/mdickinson.dyndns.org\/php\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/853\/revisions"}],"predecessor-version":[{"id":856,"href":"https:\/\/mdickinson.dyndns.org\/php\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/853\/revisions\/856"}],"wp:attachment":[{"href":"https:\/\/mdickinson.dyndns.org\/php\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=853"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mdickinson.dyndns.org\/php\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=853"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mdickinson.dyndns.org\/php\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=853"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}