OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Can I block sql injecton attack using urlscan?

From: joonh lee (fruuppempal.com)
Date: Tue Apr 22 2003 - 04:08:40 CDT


Hi..
I want to block sql injection attack..
My server has vulnerability about this..-_-;;

Some people say remedy the source..but I can't do that.-_-;;
It's not my source so It will take many time i think..

So I tried to block sql injection attack using urlscan..
But urlscan couldn't filter urlsequences after "?".

This is is my DenyUrlSequences^^
' ; Prevent SQL injection
-- ; Prevent Sql Injection

Who has good idea about blocking this?
Please tell me how to do that..^^

have a good day