Joined: Apr 06, 2006 Posts: 2415 Location: Iowa, USA
Posted:
Thu Aug 28, 2008 7:15 am
lonk, that just looks like a malformed attack. My .htaccess fix won't stop that because there are no spaces between DECLARE and the @, however if that is the actual text you got from Sentinel that probe can't possibly do anything. It doesn't look syntactically correct in any SQL I am aware of.
Unfortunately I cannot provide the script any longer simply because since the htaccess edit I haven't received ANY scripts (hundreds) that made it through. But I do remember that there were no underscores in the script. Perhaps this is a deliberate attempt to bypass any type of script spoiler, who knows.
View next topic View previous topic
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum