­
Marco's SQL Injection, by marco maria leoni - Joomla Extension Directory

Introduction

Site Security

This plugin adds a simple but, in most cases, fondamental protection against SQL injection and LFI (local files inclusion) attacks. It checks data sent to Joomla and intercepts a lot of common exploits, saving your site from hackers.


  • Filters requests in POST, GET, REQUEST and blocks SQL injection / LFI attempts.
  • Notifies you by e-mail when a alert is generated.
  • Protect also from unKnown 3rd Party extensions vulnerability.
  • White list for safe components (at your risk ;) )
  • automatic ip blocking on attack

Enable mail report and prepare yourself to be scared!

Anyway remember that security it is a 'forma mentis', not a plugin!

HISTORY

Version 1.4 Apr 28th, 2014:
* minor code fixes (not security related)
* default table type set by DB engine
* table creation by sql install file

Version 1.2 Mar 26th, 2013:
* Joomla! 3.0 compatility & coding style
* try - catch table checking
* InnoDB table support
* it works fine, nothing else to do on J2.5 ;)

Version 1.1 (Mar 10th, 2011)
* ip auto banning on attack (ip blocking)
* RegEx improvements to intercept more SQL attacks

Version 1.0 (Jan 7st, 2011)
* Joomla! v1.6 compatibility
* send mail also when error is raised
* minor code optimization

Version .98a (Jun 1st, 2010) Thanks to Jeff
* fixed backtics matching
* fixed union all matching
* fixed ....// exploit
* added more info to report mail

Version .98 (May 29th, 2010)
first release.

Please, keep in mind, I repeat: this plugin intercepts a lot of common exploits, not ALL!! this should be intended as an help, this is not "THE SOLUTION".

A MUST for every joomla!



Posted on 12 November 2011
Iam a site builder in Greece and have more tha 50 joomla sites online.

This plugin has save mu job and my money for many many times, has help me to found an attacker and go him to the judge... except saving my sites ofcourse!

A REALLY BIG THANK YOU FOR PROVIDING US THIS PLUGIN!

I 10000% suggesting it with closed eyes!

Inform me when u will make a donation system on your site!

IT'S WORKING!



Posted on 18 October 2011
this plugin really do the job very excellent. it help me a lot! my website got attacked from few blacklist country ip and trying to inject my website, steal the password esc. this plugin block them all. thanx a lot!

Greatest Plugin



Posted on 18 September 2011
This is an excellent plugin,I've suffered so much in the past from sql injection until this plugin made it so easy for my at least to find out which extension the hacker is trying to get into.

Great work Marco, I've been using joomla since it was Mambo never wrote a review before, after using this plugin and see it working perfectly.

Thanks again

Great plugin!



Posted on 20 July 2011
Very good, use it on all my sites. Thanks Marco!
Thank you for this great plugin, it's been 6 months I use this plugin and the results are amazing! direct report I received via email and I also immediately block the attacker ip address.



TY Marco

Great Plugin



Posted on 22 May 2011
This plug-in is simple and it does what it claims. On one of my site people kept trying to exploit a vulnerability on Rokdownload ... I found out about it because of this extension.



thank you Marco
You state in your description that all I have to do after installing the plug in is turn on my mail reporting. How do I do that? I looked in my global configuration and could not find any thing on mail reporting?
This plugin detected an attack on our website, within five minutes we have stopped it by blocking the IP address the attack came from.

We are now planning to deploy this plugin on all our websites.



Thank you Marco for a job well done.

excellent



Posted on 21 March 2011
Simple, and does what it says. I also suggest sending letters in html, and with whois link - so it will be no more necessary to copy-paste IP, go to whois site etc...

Does the job!



Posted on 25 January 2011
From time to time our site gets these automated attacks, trying to access the site and probably its email system to send spam. As soon as I get the message I block the IP address.

Thank you for this great and simple extension!
Marco's Google(TM) bot access
Free

Marco's Google(TM) bot access

By marco maria leoni
Site Access
This plugin allows to spiders and robots, like Google(TM), MSNBot(TM) or Yahoo(TM), to access the pages of the site reserved to the 'Registered' users. Sometimes you have to protect interesting contents to get users' registration for commercial purposes or simply to create a community. But if content are not accessible, how can users know about their existance? With this plugin the search engine...
Marco's noFollow
Free

Marco's noFollow

By marco maria leoni
SEO & Metadata
This plugin allows you to add "rel" and "target" attributes to all outgoing links in articles on your Joomla!, so you can avoid to disperse the Page Rank on the web by setting the attribute rel = "nofollow" on all outbound links, and you can keep visitors on your site by setting the target = "_blank" attribute. Configuration is very easy, simply select the action to be taken for the two attribute...
Marco's parallax background scroller
Free

Marco's parallax background scroller

By marco maria leoni
Page Background
A plugin for parallax background scrolling in Joomla! This is a nice background scrolling effect with a simulation of a pseudo parallax effect. You can insert one or more image in your articles and define an horizontal stripe (view port) to see the images as they was really a landscape through a window. See this plugin in action! Features . Easy to use and configure . CSS3 and responsive . plugi...
Marco's buy me a beer
Free

Marco's buy me a beer

By marco maria leoni
Donations
This implementation of Buy me a beer in Joomla!, is a smart & funny way to get a donation without the need to specify ethical reasons: "Do you think my job was useful? Ok, buy me a beer, I just wanna have a drink, not save the world!" Features works on multilingual site; every text in the donation form can translated using Joomla's language override feature; automatic PayPal's interface languag...
Marco's PrestaShop Authentication
Free

Marco's PrestaShop Authentication

By marco maria leoni
Site Access
This plugin allows to customers of a PrestaShop™ e-commerce to access the Joomla! site without a new registration. This is a fast authentication bridge between the two systems. Prestashop to Joomla bridgeThis plugin allows to use an existent PrestaShop e-commerce to authenticate its users on a Joomla installation. Features plugin works on J2.5 and J3.x sites; no need of double registration;...

Marco's SQL Injection

Version:
1.4
Developer:
marco maria leoni
Last updated:
Nov 18 2014
10 years ago
Date added:
Nov 18 2014
License:
GPLv2 or later
Type:
Free download
Includes:
p
Compatibility:
J3
Download

This extension does NOT implement the Joomla! Update System

Score:


Write a review