How to track down Invalid utf8 character string

Viewed 190

Running a search in PHPMyAdmin for an ip address to unblock from a WordPress plug in, I get this on one of the tables:

Warning: #1300 Invalid utf8 character string: '\x8B\x08\x00\x00\x00\x00\x00\x00\x03\x14\xD6y8\x15\xEF\x17\x0...'

Warning: #1300 Invalid utf8 character string: '\x8B\x08\x00\x00\x00\x00\x00\x00\x03\x00\x1E\x80\xE1\x7Fa:2:{...'

I tried to search for part of the strings, but cannot find where they are in the db. These look suspicious to me, I've had some SQL injection compromises in the past and I'm fearing that's what it may indicate.

How do I track down where these strings actually are in the db if I cannot find by the PHPMyAdmin search?

Thank you.

1 Answers

Those look like gzip headers which are missing their leading \x1f. I expect it's there but not part of the warning because \x1f is a valid UTF-8 character but \x8b is not.

1F       2-byte magic number of a gzip file
8B       |
08       compression method (08 = deflate)
00       1 byte header flags (00 = it's probably compressed text)
00       4 byte timestamp
00       |
00       |
00       |
00       Extra flags
03       Operating System (03 = Unix)

After that, data begins.

Something is trying to read gzipped text as UTF-8.

Related