Injection Scanner
Unlogged Injections
| User |
Post |
Chella Member Posts: 4
|
Posted: 2008-04-22 11:28:11
|
Hullo!
I recently installed the injection scanner and it works well, but I'm having some injections that are being logged in my "Latest Visitor" stats, and not in Injection Scanner, here are some examples taken from the log:
/home.php?subaction=http%3A%2F%2Fwww.obrasmecanicasch.com%
2Fomch%2Fimg%2Fanawuho%2Fledego%2F&id=120733
/home.php?subaction=http%3A%2F%2Fwww.clubnataciotortosa.com%
2FUserFiles%2FFile%2Fedut%2Fjezin%2F&id=12
/home.php?start_from=http%3A%2F%2Fwww.zlotow.biz%
2Fradiomariana2%2Frawi%2Fayutuqi%2F&ucat=&arc
...and so on and so forth.
Is there another anything I can add to the exploits.txt so Injection Scanner will recognise them? |
Scott Admin Posts: 211
|
Posted: 2008-04-22 16:46:38
|
| You can add http%3A%2F%2F to the exploits file to prevent all hexadecimal-encoded URLs from being used in the query string. |
Page:
[ 1 ]
New Post
You must be logged in to post on the discussion boards.