Forum Discussion
We saw something similar in October of last year.
16,433 searches for the letter e and a significant number of searches for the number 20. And who is Larry Freeman?
The rest of the unusual SQL-related searches were fewer in quantity.
I thought searches were rate-limited, but perhaps I'm wrong about that.
We have the same thing w/ searches containing "1" & then some code:
These all happened within the last 30 days.
These searches don't cause any mal effects - the code doesn't actually end up running on the site. So I wouldn't call it a security risk - but I also don't know a ton about this topic.
- Notmark-VFZMentor
FYI, we've also raised this question to Khoros directly and have received a comforting response:
"We can confidently confirm that the mentioned query, although looks like SQL, is actually a Khoros(Lithium) specific language - LiQL which is well protected against most of common attacks like SQL injections.
You can share a couple of articles to anyone who would want to understand the same with below links:
1. https://community.khoros.com/t5/Community-FAQ-s-from-Support/Is-LiQL-vulnerable-to-SQL-injection-attacks/ta-p/281334
Related Content
- 3 years ago
- 7 years ago