Page is a not externally linkable
- Microsoft
-- Microsoft IIS Web Server and ASP.NET
---- Mass IIS attack under way


aleksl - 10:05 pm on Jun 11, 2010 (gmt 0)


I concur, we'were attacked, but they didn't get through. This is a classic sql injection. It is a 64-bit encoded string that executes Microsoft SQL server script. They append their own string to every character field in your database.

We were hit by almost identical attack 2 years ago, when we were unprepared. But the script is "lazy" enough that it'll just append everywhere...which leads me to believe they are there for collateral damage.

You'd need a database scan script to look through all character fields if your DB is large enough.


Thread source:: http://www.webmasterworld.com/microsoft_asp_net/4151390.htm
Brought to you by WebmasterWorld: http://www.webmasterworld.com