Sue,
I have been hit continuously with SQL Injection Attack attempts. When I first discovered it I contacted Scott and he was a tremendous help.
Here is some more detail on what that attack is trying to do:-
http://ppshein.wordpress.com/tag/dos/
There is an article on sql injection with DNN here:-
http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1930/Default.aspx
In my case I was not compromised however with each attack it was throwing exceptions. The continuous attacks cased a DoS situation.
I have since installed URLScan from Microsoft. Since I installed URLScan on Sept 20th, I have had 4,271 attempts as of this writing.
I decoded the encrypted URL and saw the complete code. They are attempting to insert some JS code from an external site, so when the page loads the code would fire. I attempted to manually download to code to see what they were trying to, but it got flagged by my AntiVirus as a Trojan.. That was enough for me. I did check my tables and it appears that they were unsuccessful in their attempts.
|