cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
289
Views
0
Helpful
1
Replies

CSA - asprox and supplemental SQL injection protection

RichardSW
Level 1
Level 1

For those of you running CSA to protect your IIS web server, which may also be utilizing SQL, you may want to supplement your existing DAC rules.

Asprox/Danmec obfuscates the sql injection by hex encoding it inside a CAST statement, like so:

The process 'C:\WINNT\system32\inetsrv\inetinfo.exe' (as user NT AUTHORITY\SYSTEM) attempted to receive the data '/page.asp?;DECLARE%20@S%20CHAR(4000);SET%20@S=CAST(0xhe operation was allowed by a rule (rule defaults).

In the rule originally named "IIS and Apache Web Servers, Common SQL Server command injection exploits", open the data set of the same name. Add the following:

*DECLARE*SET*CAST*

In case you have a page that is vulnerable to an sql injection (and aren't aware yet), you are now protected.

1 Reply 1

fheelip45
Level 1
Level 1

Nice catch, thank you for the information.