View Single Post
  #8 (permalink)  
Old 03-02-2009, 07:00 PM
Corobori's Avatar
Corobori Corobori is offline
WebProWorld Member
 
Join Date: Jan 2004
Location: Concepcion, Chile
Posts: 47
Corobori RepRank 0
Default Re: Happy Monday morning: Site is listed as suspicious

Quote:
Originally Posted by Dubbya View Post
It appears that you are the victim of a cross site scripting attack. Specifically a "SQL injection attack".
Well actually that was my 1st thought and I checked the db for the keywords you're listing besides .js and ken.gif and didn't find one suspicious row.
To be honest I learned SQL Injection the hard way a while ago and user's input is filtered and also we set a specific SQL user unable to read sysobjects and its friends.
What puzzled me was that the script thing that I could see appeared on the top of the html source not mixed in between the data as I haven't seen on SQL Injection before.
__________________
jean-luc
www.corobori.com
Reply With Quote