<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SQLCleanup.com - SQL Injection Attack Cleanup Tools &#187; SQL Cleanup Cleans &#8220;LizaMoon&#8221; Injection Attacks &#8211; SQL Injection Cleanup @ SQLCleanup.com</title>
	<atom:link href="http://www.sqlcleanup.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sqlcleanup.com</link>
	<description>SQL injection attack made easy.  The leading tool for cleaning up your database!</description>
	<lastBuildDate>Sun, 15 May 2011 17:14:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<item>
		<title>SQL Cleanup Cleans &#8220;LizaMoon&#8221; Injection Attacks</title>
		<link>http://www.sqlcleanup.com/2011/sql-cleanup-cleans-lizamoon-injection-attacks/</link>
		<comments>http://www.sqlcleanup.com/2011/sql-cleanup-cleans-lizamoon-injection-attacks/#comments</comments>
		<pubDate>Fri, 01 Apr 2011 19:20:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Topics]]></category>

		<guid isPermaLink="false">http://www.sqlcleanup.com/?p=19</guid>
		<description><![CDATA[Click the &#8220;Order Now&#8221; link in the top menu to purchase.  Simply follow the included instructions to remove all occurrences of the attack from your Microsoft SQL server database.  Also includes tips on stopping subsequent attacks.]]></description>
			<content:encoded><![CDATA[<p>Click the &#8220;Order Now&#8221; link in the top menu to purchase.  Simply follow the included instructions to remove all occurrences of the attack from your Microsoft SQL server database.  Also includes tips on stopping subsequent attacks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sqlcleanup.com/2011/sql-cleanup-cleans-lizamoon-injection-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SQL Injection Attack Cleanup Script + FREE Tools</title>
		<link>http://www.sqlcleanup.com/2010/sql-injection-attack-cleanup-script/</link>
		<comments>http://www.sqlcleanup.com/2010/sql-injection-attack-cleanup-script/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 14:08:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Topics]]></category>

		<guid isPermaLink="false">http://www.gardencitynet.com/?p=4</guid>
		<description><![CDATA[Database Attacked? FIX IT NOW! NOW ONLY $75 •IMMEDIATE DOWNLOAD • SUPPORTS Microsoft SQL 2000/2005/2008 • FAST &#38; EASY CLEANUP • FREE TECH SUPPORT (EMAIL) • FREE PREVENTION CODE • FREE SQL BACKUP SCRIPT •100% CUSTOMER SUCCESS RATE&#160; (Don&#8217;t have a paypal account?) UPDATED: MAY 15, 2011 NOW INCLUDED: Script for the &#8220;LIZAMOON&#8221; and  &#8220;google-anallytics&#8221; [...]]]></description>
			<content:encoded><![CDATA[<div style="float: right; width: 200px; margin-left: auto; margin-right: auto; padding: 10px;"><span style="font-size: 18px; font-weight: bold; background-color: yellow;">Database Attacked?<br />
FIX IT NOW!<br />
NOW ONLY $75</span><br />
<strong>•IMMEDIATE DOWNLOAD<br />
• SUPPORTS Microsoft SQL 2000/2005/2008<br />
• FAST &amp; EASY CLEANUP<br />
• FREE TECH SUPPORT (EMAIL)<br />
• FREE PREVENTION CODE<br />
• FREE SQL BACKUP SCRIPT<br />
•100% CUSTOMER SUCCESS RATE</strong>&nbsp;</p>
<form action="https://www.paypal.com/cgi-bin/webscr" accept-charset="UNKNOWN" enctype="application/x-www-form-urlencoded" method="post">
<input maxlength="67108863" name="cmd" size="20" type="hidden" value="_xclick" />
<input maxlength="67108863" name="business" size="20" type="hidden" value="prezzatech@gmail.com" />
<input maxlength="67108863" name="item_name" size="20" type="hidden" value="SQL INJECTION CLEANUP SCRIPT - SQL2000/2005" />
<input maxlength="67108863" name="item_number" size="20" type="hidden" value="SQL002" />
<input maxlength="67108863" name="amount" size="20" type="hidden" value="$75" />
<input maxlength="67108863" name="no_shipping" size="20" type="hidden" value="0" />
<input maxlength="67108863" name="return" size="20" type="hidden" value="http://www.sqlcleanup.com/thanks" />
<input maxlength="67108863" name="no_note" size="20" type="hidden" value="1" />
<input maxlength="67108863" name="currency_code" size="20" type="hidden" value="USD" />
<input maxlength="67108863" name="lc" size="20" type="hidden" value="US" />
<input maxlength="67108863" name="bn" size="20" type="hidden" value="PP-BuyNowBF" />
<input alt="PayPal - The safer, easier way to pay online!" maxlength="67108863" name="submit" size="20" src="https://www.paypal.com/en_US/i/btn/btn_buynowCC_LG.gif" type="image" /> <img src="https://www.paypal.com/en_US/i/scr/pixel.gif" border="0" alt="" width="1" height="1" /><br />
(<a href="http://www.sqlcleanup.com/nopaypal">Don&#8217;t have a paypal account?</a>)<br />
</form>
</div>
<p><strong>UPDATED: MAY 15, 2011</strong></p>
<p><strong>NOW INCLUDED: Script for the &#8220;LIZAMOON&#8221; and  &#8220;google-anallytics&#8221; trojans. </strong>If you see fake Google Analytics code + links, we have a script to clean this that&#8217;s now included!</p>
<p>Is your Microsoft IIS based web site getting hit with SQL Injection attacks? Are you seeing lots of javascript embedded in your database?</p>
<p>These situations can be a total pain to cleanup, which is why we’ve written the script for you.</p>
<p><strong>Here’s what it does:</strong></p>
<ul>
<li>Searches all attackable tables and fields in your <strong>Microsoft SQL Server database (versions 2008, 2005, or 2000 supported)</strong></li>
<li>Counts the number of rows that have been hacked</li>
<li>Cleans the string out of the fields, including text/ntext columns</li>
<li>VOILA! You are back up and running.</li>
</ul>
<p>Note that this is for attacks that use string insertion — truncation or deletion will not be fixed by this script.</p>
<p><strong>INCLUDES FREE EXTRAS:</strong> SQL injection prevention code (for Active Server Pages and Microsoft .NET) and a free script for automating daily SQL Server backups to disk.</p>
<p><strong>Press the “Buy Now” button below — only $75</strong></p>
<form action="https://www.paypal.com/cgi-bin/webscr" accept-charset="UNKNOWN" enctype="application/x-www-form-urlencoded" method="post">
<input maxlength="67108863" name="cmd" size="20" type="hidden" value="_xclick" />
<input maxlength="67108863" name="business" size="20" type="hidden" value="prezzatech@gmail.com" />
<input maxlength="67108863" name="item_name" size="20" type="hidden" value="SQL INJECTION CLEANUP SCRIPT - SQL2000/2005" />
<input maxlength="67108863" name="item_number" size="20" type="hidden" value="SQL002" />
<input maxlength="67108863" name="amount" size="20" type="hidden" value="75" />
<input maxlength="67108863" name="no_shipping" size="20" type="hidden" value="0" />
<input maxlength="67108863" name="return" size="20" type="hidden" value="http://www.sqlcleanup.com/thanks" />
<input maxlength="67108863" name="no_note" size="20" type="hidden" value="1" />
<input maxlength="67108863" name="currency_code" size="20" type="hidden" value="USD" />
<input maxlength="67108863" name="lc" size="20" type="hidden" value="US" />
<input maxlength="67108863" name="bn" size="20" type="hidden" value="PP-BuyNowBF" />
<input alt="PayPal - The safer, easier way to pay online!" maxlength="67108863" name="submit" size="20" src="https://www.paypal.com/en_US/i/btn/btn_buynowCC_LG.gif" type="image" /> <img src="https://www.paypal.com/en_US/i/scr/pixel.gif" border="0" alt="" width="1" height="1" /><br />
(<a href="http://www.sqlcleanup.com/nopaypal">Don&#8217;t have a paypal account?</a>)<br />
</form>
]]></content:encoded>
			<wfw:commentRss>http://www.sqlcleanup.com/2010/sql-injection-attack-cleanup-script/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>How to find + stop SQL injection attacks</title>
		<link>http://www.sqlcleanup.com/2008/how-to-find-stop-sql-injection-attacks/</link>
		<comments>http://www.sqlcleanup.com/2008/how-to-find-stop-sql-injection-attacks/#comments</comments>
		<pubDate>Sun, 01 Jun 2008 14:07:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Topics]]></category>

		<guid isPermaLink="false">http://www.sqlcleanup.com/?p=13</guid>
		<description><![CDATA[There&#8217;s a lot of stuff out there about SQL injection attacks (including our handy cleanup script), but there&#8217;s not much that will help you figure out how to stop these attacks from occurring. First, let&#8217;s talk about what a SQL Injection Attack really is. Some people think it&#8217;s a virus of sorts, that is &#8220;inside [...]]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s a lot of stuff out there about SQL injection attacks (including our <a href="http://www.sqlcleanup.com/2009/sql-injection-attack-cleanup-script/">handy cleanup script</a>), but there&#8217;s not much that will help you figure out how to stop these attacks from occurring.</p>
<p>First, let&#8217;s talk about what a SQL Injection Attack really is.  Some people think it&#8217;s a virus of sorts, that is &#8220;inside your site.&#8221; Not the case.  These are bot attacks by other virus infected computers. They simply use a brute force approach of scanning URLs that take POST/GET inputs and attempt to send their own data to them.</p>
<p>So, how do you track these down and stop them?  For web sites powered by Microsoft&#8217;s IIS, here are our suggestions:</p>
<ol>
<li><strong>Look at your IIS logs<br />
</strong>Try searching for the word &#8220;DECLARE&#8221; or &#8220;EXECUTE.&#8221; If you&#8217;ve been hit by an attack, these will more than likely show up in your IIS logs &#8212; at least for any attack that was attempted using &#8220;GET&#8221; posts.  If you do find any instances of &#8220;DECLARE&#8221; or &#8220;EXECUTE&#8221; these are the pages to start with.</li>
<li><strong>Use centralized database connection handling<br />
</strong>Simple, make a centralized file (e.g. connection.asp if you are using ASP &#8212; see our <a href="http://www.sqlcleanup.com/connection.txt" target="_blank">free example</a>) that handles all of your DB access.  This way, it&#8217;s easier to make sure that you are SQL encoding your pages.  You can easily search queries for &#8220;DECLARE&#8221; and &#8220;EXECUTE&#8221; and stop the attacks dead in their tracks.</li>
<li><strong>Implement a site wide solution<br />
</strong>If you are running your own server, we highly recommend ISAPI_Rewrite from HeliconTech (<a href="http://www.helicontech.com/isapi_rewrite">http://www.helicontech.com/isapi_rewrite</a>). This is an ISAPI filter that allows you to do a variety of things, including scan URL data.  This will stop 99% of attacks without changing ANY code on your site!</li>
</ol>
<p>If you have any questions, tips, or comments, please use the contact us link above.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sqlcleanup.com/2008/how-to-find-stop-sql-injection-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scheduled restart of SQL server</title>
		<link>http://www.sqlcleanup.com/2008/scheduled-restart-of-sql-server/</link>
		<comments>http://www.sqlcleanup.com/2008/scheduled-restart-of-sql-server/#comments</comments>
		<pubDate>Tue, 27 May 2008 01:17:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Topics]]></category>

		<guid isPermaLink="false">http://www.sqlcleanup.com/?p=12</guid>
		<description><![CDATA[As you may notice, Microsoft SQL Server will gradually consume more and more memory after it starts&#8230;Most people (us included) will wonder if this means that there are memory leaks or unclosed connections.  While you should make sure to close all unused connection, this is actually normal behavior &#8212; just check the Microsoft knowledge base [...]]]></description>
			<content:encoded><![CDATA[<p>As you may notice, Microsoft SQL Server will gradually consume more and more memory after it starts&#8230;Most people (us included) will wonder if this means that there are memory leaks or unclosed connections.  While you should make sure to close all unused connection, this is actually normal behavior &#8212; just check the Microsoft knowledge base <a href="http://support.microsoft.com/kb/321363/en-us" target="_blank">#321363</a>. </p>
<p>While there are a variety of memory configuration options, we have a nice bandaid fix: restart SQL server during off hours.  Simply make a .bat file with the code below and use windows scheduler to run the file when traffic is low:</p>
<p>@ECHO OFF<br />
NET STOP SQLSERVERAGENT<br />
NET STOP MSSQLSERVER<br />
NET START MSSQLSERVER<br />
NET START SQLSERVERAGENT</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sqlcleanup.com/2008/scheduled-restart-of-sql-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SQL 2005: Truncating Log Files and Recovering Space</title>
		<link>http://www.sqlcleanup.com/2008/sql-2005-truncating-log-files-and-recovering-space/</link>
		<comments>http://www.sqlcleanup.com/2008/sql-2005-truncating-log-files-and-recovering-space/#comments</comments>
		<pubDate>Fri, 04 Apr 2008 12:34:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Topics]]></category>

		<guid isPermaLink="false">http://www.sqlcleanup.com/?p=14</guid>
		<description><![CDATA[A common issue for users of SQL Server databases is disk space and the size of the physical log file and database. While we&#8217;re not going to attempt to make &#8220;one size fits all&#8221; statement on database maintenance plans, we though it would be helpful to provide a few suggestions that will help you trim the [...]]]></description>
			<content:encoded><![CDATA[<p>A common issue for users of SQL Server databases is disk space and the size of the physical log file and database. While we&#8217;re not going to attempt to make &#8220;one size fits all&#8221; statement on database maintenance plans, we though it would be helpful to provide a few suggestions that will help you trim the size of your files when you are in a pinch.</p>
<p><strong>Steps to truncating log files and shrinking your database:</strong></p>
<p><strong>1.  Get the physical names of your database file (MDF) and log file (LDF):<br />
</strong>Run the following system stored procedure:</p>
<p style="padding-left: 30px; text-align: left;"><code>use &lt;yourdatabasename&gt;<br />
</code><code>exec sp_helpfile</code></p>
<p>This command will return a variety of information, including the physical size (the &#8220;size&#8221; column) and the path and name of your database and log files (in the &#8220;filename&#8221; column). </p>
<p>Record the name of the file from the &#8220;filename&#8221; colunm, excluding the path and file extension (e.g. if filename contains &#8220;C:\sqldatabases\yourdatabase_data.mdf&#8221; you want to save the string &#8220;yourdatabase_data&#8221;)</p>
<p><strong>2. Truncate the database and shrink the database<br />
</strong>The following set of SQL will shrink your database and &#8220;truncate&#8221; the log file. File in the parmaters surrounded by &lt;&#8230;&gt;.  Note that you&#8217;ll need the two filename values from step 1.</p>
<p style="padding-left: 30px;"><code>USE &lt;yourdatabasename&gt;<br />
GO<br />
BACKUP LOG &lt;yourdatabasename&gt; WITH TRUNCATE_ONLY<br />
GO<br />
DBCC SHRINKFILE (&lt;yourdatabaselogfilename&gt;, 1)<br />
GO<br />
DBCC SHRINKFILE (&lt;yourdatabasedatafilename&gt;, 1)<br />
GO<br />
exec sp_helpfile</code></p>
<p>When complete, this script will output the same information as in step 1.  Compare the new size with the old.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sqlcleanup.com/2008/sql-2005-truncating-log-files-and-recovering-space/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

