Would love to see the code you used for filtering, I setup code that checks all querys for SELECT, INSERT, DECLARE, DELETE etc and redirects the user to their own malicious code
but they somehow still got through.
there is no need to guess how, look at the logs ![]()
I got an email from Web Site Mag today about SQL Injections. Includes a free scanner.
Here is the link: http://www.websitemagazine.com/content/blogs/posts/archive/2008/06/25/SQL_Injection_Detection_and_Defense.aspx