Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: RE: Problems with IIS

RE: Problems with IIS

From: Marcelo Villalón Mendez <mvillalon_at_secureit.cl>
Date: Wed, 14 Jul 2004 15:49:25 -0400

Hi Marcelo, i think you have to analyze the querystring of your pages, it seems to be a SQL-Inyection attack.
 
Most likely solution to his type of attack is to validate every parameter before do anything.
 
You also install URLScan to run with IIS (free MS software).
 
Good luck
Marcelo Villalón M.
 

        -----Mensaje original-----
        De: Marcelo Leão Caffaro [mailto:leao_at_employer.com.br]
        Enviado el: Mié 14-07-2004 7:25
        Para: webappsec_at_lists.securityfocus.com
        CC:
        Asunto: Problems with IIS
        
        

Received on Jul 16 2004

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]