• Unfortunately, we have experienced significant hard drive damage that requires urgent maintenance and rebuilding. The forum will be a state of read only until we install our new drives and rebuild all the configurations needed. Please follow our Facebook page for updates, we will be back up shortly! (The forum could go offline at any given time due to the nature of the failed drives whilst awaiting the upgrades.) When you see an Incapsula error, you know we are in the process of migration.

Sql hacker attack

Status
Not open for further replies.
Newbie Spellweaver
Joined
Jun 16, 2014
Messages
16
Reaction score
0
Hello.
Every week i have been hacked by Ukrine hacker.
He is braking up my server via SQL injection and i dont know how he did it. Mostly he just playing around.. Add items to account.. Add credits or just create some new char to someones account.
I have enabled FireWall and only necessary ports are opened.
Anyone can help?
P.S - I'm using MVCore premium version. Microsoft Server 2012 & SQL 2008
 
Joined
Apr 22, 2013
Messages
710
Reaction score
49
Use 2 IP's on your server
Admin IP - for RDP (3389) & SQL Remote (1433)
Public IP - MuServer (CS+GS) & Website
Limit their connection in Advance Firewall Settings on Allowed Local IP

If injection is done via Web, better change CMS (MuOnlineWebs or WebEngine)

Some SQL Server Tips:
Rename user "sa" to your preferred name
Use longer password with random combination

***Check your files for Trojan Virus
***Install MSE Anti-Virus on Server
***Limit Connection of Port RDP & SQL to your IP Range
 
Upvote 0
Status
Not open for further replies.
Back
Top