SQL Injection

the Cisco IPS Sensor is showing multiple SQL INJECTION alerts e.g Generic SQL Injection, SQL Query in HTTP Request.

problem is HOW i can Drill down and see which PC or APP in the Web Server is generating it.

in Attacker IP i got my PROXY Appliance IP
and in Victim IP i got some guy sitting in Korea.

any ideas
btan Exec Consultant Commented:
To know the web app attack, it shd surfaced from the http log and if proxy is L7 aware, it shd be able to see it. Also for traffic dump is ideal to sieve through the L7 info. Can try having dump out the collected log or use sniffer. See this


Normally if the proxy is also a web app firewall, the info you needed will be easily available. There is modsecurity for instance. The proxy log will show the http get and post or relevant xml based request that ids or ips maynot have the visibility since they are relying on pattern not contextual info to trigger alert
Rich Rumble Security Samurai Commented:
Sounds like a false positive, and or one of your users machines has attacked someone in Korea (it's usually the other way around :) Cisco should be able to help you, have you contacted TAC?
osloboy Author Commented:
is CISCO TAC is same like ORACLE, where you can find KBs and other information
Rich Rumble Security Samurai Commented:
If you pay for cisco gear, typically you pay for support and TAC is cisco's live support, you open a case and an engineer calls you or emails you. I don't use Cisco IPS so I might not be able to help much more.
osloboy Author Commented:
thanks a lot for the Light in the dark.

what Switches/Filters i should use in WireShark to get this task done

any specific

osloboy Author Commented:
