Hi,
Both examples have syntax errors.
1. – is not a valid character, it should be replaced with --.
2. p20WAITFOR isn’t valid either.
1%27+waitfor+delay+%2700%3A00%3A05%27-- would be a valid syntax.
I will change the firewall rule to catch similar issues.
-
This reply was modified 7 years ago by
nintechnet.
Glad to hear that, thank you.
/ChriStef.
Hello again. Could you see the new attempts below:
%20AND%201679%3D%28SELECT%201679%20FROM%20PG_SLEEP%285%29%29–%20snlo
%20AND%201679%3D%28SELECT%201679%20FROM%20PG_SLEEP%285%29%29
%3BSELECT%20PG_SLEEP%285%29–
%29%3BSELECT%20PG_SLEEP%285%29
%27zfxmjA%3C%27%22%3EBoaAOC
%27%28.%2C%22%22%27%29%29%27
What they trying to do?
-
This reply was modified 6 years, 11 months ago by
ChriStef.
They are attempts to probe PostgreSQL. That’s a bit strange because WordPress uses only MySQL/MariaDB, not PostgreSQL !
Thank you for your insights. Keep it strong…
Do you suggest to me to add some custom rules?
You can safely ignore them, they don’t affect WordPress.
Maybe I’ll adjust some rules just to kick them out, but it is not really important.