All Tagssql injection (RSS)
  • URLScan 3.0 RTW: [AlwaysAllowedQueryStrings]

    Doing some testing, currently, and running into some issues with this. We've got a couple cases where things like 'cast' or 'open' are appropriate for our webpages. I've setup an AlwaysAllowedQueryStrings section: [AlwaysAllowedQueryStrings] branch=Openshaw branch=Newcastle+upon...
    Posted to Forum by jgraham on 09-02-2008, 9:46 AM
  • Re: UrlScan 3.0 Beta not capturing SQL Injection

    Rovastar, I can confirm that the workaround that KentZhou posted works. I have included below the contents of the RuleList section in the UrlScan.ini as I have it in my test box. After changing the rule though I issued an iisreset /restart command before I tested so the UrlScan.ini's settings were...
    Posted to Forum by apajlopez on 08-18-2008, 8:51 AM
  • Re: Anyone know about www.nihaorr1.com/1.js?

    Hi, Im a System Administrator of a Hosting Company, and one of our website has been hacked with SQL injection, At first the hacker inserted nihaorr1.com/1.js most of the website table are being affected with this attacked, after that incident I developed a SQL validation that is similar on the asp script...
    Posted to Forum by ejhay on 05-21-2008, 10:11 PM
  • Re: Anyone know about www.nihaorr1.com/1.js?

    Hi, Im a System Administrator of a Hosting Company and one of our website has been hack with SQL injection, At first the hacker inserted nihaorr1.com/1.js most of the website table are being affected with this attacked, after I created that a created a SQL validation like one that you have posted in...
    Posted to Forum by ejhay on 05-21-2008, 10:08 PM
  • Re: Anyone know about www.nihaorr1.com/1.js?

    Hi, The use of this script at pointing to nihaorr1.com is only the latest method of attack used by this attacker. This guy has been hacking at a clients web site for a long time and usually does so through various proxy servers. For those looking for a tool to view IIS log files, check out this program...
    Posted to Forum by alexhiggins732 on 04-26-2008, 10:53 PM
  • SQL Injection Attacks on IIS Web Servers

    This thread will contain the latest information regarding recent reports that have surfaced stating that web sites running on Microsoft’s Internet Information Services (IIS) 6.0 have been compromised. These reports allude to a possible vulnerability in IIS or issues related to Security Advisory 951306...
    Posted to Forum by bills on 04-25-2008, 11:41 PM
  • Re: Anyone know about www.nihaorr1.com/1.js?

    I would advise anyone affected by this attack to activate the SQL profiler (or equivalent) and set it to record only EXEC commands. If your website then becomes infected again you can quickly scroll through the profiler output and find the "suspicious" command where the injection has entered...
    Posted to Forum by nhertz on 04-24-2008, 5:11 PM
Page 1 of 1 (7 items)
Microsoft Communities