Page 2 of 2 FirstFirst 12
Results 11 to 14 of 14
  1. #11
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: Woooah! Mystery related to Backup mySQL

    Quote Originally Posted by Feznizzle View Post
    I found some 56 notes in the admin activity log that said this: "ALERT: Please review for possible XSS activity:"

    All (that I looked at) had my ip in front of them.

    Should I be freaked out by that?
    Freaked out? No.
    Should you look at them? Yes.
    That flag is set when it discovers that someone using your Admin has submitted data in an <input> form field that contains potentially risky content like < and > symbols such as could be used to stuff <script> tags into content.
    The flag is set to tell you to make sure that you knew about the content being submitted, by basically alerting you to pay attention to those log records specifically.

    If you did post the content it mentions and intended it to contain whatever it contains, then of course there's nothing to worry about.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  2. #12
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: Woooah! Mystery related to Backup mySQL

    Is your "backup mystery" resolved now?
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #13
    Join Date
    Apr 2010
    Posts
    900
    Plugin Contributions
    0

    Default Re: Woooah! Mystery related to Backup mySQL

    rofl (at Rod's joke)
    ++++
    I think (*hope*) I figured it out. I had created a bunch of tables in openoffice, turned them into html, then grabbed all the <tr> cells and dumped them into preformatted product cross-referrence sheets. The hotlinks were all domain nuetral, went something like this:
    <TD STYLE="border-top: 1px solid #000000; border-right: 1px solid #000000" WIDTH=105 ALIGN=CENTER><U><A HREF="/Material_Handling_Storage/Bins_Boxes_Totes/Storage_Containers/SomeCategory">VIEW</A></U></TD>

    However, due to some quirk, openoffice kept giving me hrefs like this:
    <TD STYLE="border-top: 1px solid #000000; border-right: 1px solid #000000" WIDTH=105 ALIGN=CENTER><U><A HREF="file:///Material_Handling_Storage/Bins_Boxes_Totes/Storage_Containers/SomeCategory">VIEW</A></U></TD>

    I just the current admin log sql, found a single warning pointing at "file://" as being the trigger.

    I will def be keeping a close eye on this, can't imagine how someone could highjack my sessions! Or why, for that matter. The thought is that either it was just that "file://" business (most likely, I hope) or there was a trojan in my template or one of my mods (yikes!).
    Last edited by Feznizzle; 27 Aug 2013 at 05:29 PM.

  4. #14
    Join Date
    Apr 2010
    Posts
    900
    Plugin Contributions
    0

    Default Re: Woooah! Mystery related to Backup mySQL

    Didn't see all your posts b4 I posted, DrByte.

    I think Rod was right, the SQL going on a diet must have been the purged admin log. Though I am confused why it was so dramatic of a change in comparison to other purges. But, again, Rod had a pretty plausible explanation for that (Internal Error 500 causing restart and table repair).

    As for the xss stuff, I am comfortable that I triggered it myself and it was not malicious. And I don't think I have lost anything important from the dramatic DB diet.

    So yes, I think it's resolved. Thanks for the input, DrByte and Rod!

 

 
Page 2 of 2 FirstFirst 12

Similar Threads

  1. v150 Backup MYSQL Plugin 2005: Unknown MySQL server host 'localhost:3306' (1)
    By nuganics in forum All Other Contributions/Addons
    Replies: 7
    Last Post: 10 Mar 2012, 08:09 AM
  2. Backup MYSQL Plugin "backup folder is empty"
    By lorhan in forum All Other Contributions/Addons
    Replies: 6
    Last Post: 5 Oct 2010, 03:49 PM
  3. MySQL Backup
    By DarkAzrael in forum General Questions
    Replies: 2
    Last Post: 16 Nov 2007, 05:20 PM
  4. Backup MySQL Database vs using cPanel backup option?
    By IronMan101 in forum All Other Contributions/Addons
    Replies: 0
    Last Post: 30 Jul 2007, 08:46 AM
  5. Backup MYSQL Plugin - no backup button
    By mrtorrez in forum All Other Contributions/Addons
    Replies: 30
    Last Post: 29 Jun 2007, 11:13 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg