Posted on: 4/18/2013 6:56:51 AM | Views : 1247

Dear Friends 
I am looking for the desperate help from you guys, the scenario is when i am downloding the backup of our website from the production server, my microsoft security essential caugth some .asp file as which was suspicious, when i am look the path the folder was the image folder the images are uploaded through the application through file upload control, I found 6,7 .aspx pages in the code was writted on the inline to read the IIS Users , Server Users , DB Login credential etc.
when i googled it found some aspxspy attack. I am trying to find out how the aspx files reached to that folders since only jpeg and gif files validation were there
how to prevent from these kind of attacks
what kind of security measures I need to apply at application level

please help  

Go to the complete details ...