Tuesday, August 07, 2007

Hackers Injecting Script tags into SQL data fields

Recently, on one of my clients sites, I noticed that some hacker scum had placed a script tag on some of the pages of the site by hacking into the SQL database and inserting the said script tag into a data field. This means that when the page is loaded, the script is also loaded.

The location of the script that is referred to is:


The whois information for ijk.cc is:


robert kuphal
102 Greer Drive
Brunswick, GA 31520
Email: phu59@aol.com

Registrar Name....: REGISTER.COM, INC.
Registrar Whois...: whois.register.com
Registrar Homepage: www.register.com
Domain Name: ijk.cc

Created on..............: Fri, Oct 27, 2006
Expires on..............: Sat, Oct 27, 2007
Record last updated on..: Sun, Dec 24, 2006

Administrative Contact:

Andrew McDonald
102 Greer Drive
Brunswick, GA 31520
Phone: +1.9418279024
Email: phu59@aol.com

Technical Contact:

Andrew McDonald
102 Greer Drive
Brunswick, GA 31520
Phone: +1.9418279024
Email: phu59@aol.com

DNS Servers:


I will be giving Mr Robert Kuphal of Brunswick, Georgia, USA a call to ask him why a link to a script hosted on his domain has been illegally inserted into the SQL database of the site.