I have a application with userlogin and cms-system.
On all my pages there is a Sub Page_Error that send me an email when an error occur.
For some weeks I receive daily error-mails from the application because some people try to write a SQL query in the querystring.
I feel that we have done everything to avoid this kind of people to get in to our system but I would like to know if any of you have some experience about how to handle attacks like this.
Se an example here where somebody adds a query after wid=2 :
id=55&wid=2';declare%20@c%20cursor;declare%20@d%20varchar(4000);set%20@c=cursor%20for%20select%20'update%20%5B'%2BTABLE_NAME%2B'%5D%20set%20%5B'%2BCOLUMN_NAME%2B'%5D=%5B'%2BCOLUMN_NAME%2B'%5D%2Bcase%20ABS(CHECKSUM(NewId()))%257%20when%200%20then%20''''%2Bchar(60)%2B''div%20style=%22display:none%22''%2Bchar(62)%2B''abortion%20pill%20prescription%20''%2Bchar(60)%2B''a%20href=%22http:''%2Bcha ...
Go to the complete details ...