Having an SQL security problem. We run a dating type website, and someone keeps infecting our database mssql with urls that are opening when the profile is viewed. They are adding popups to one of the tables in our database (they are putting in html code that is popping up pages that are installing malacious software when teh page is viewed) It's happened about 3 times already and we keep restoring our database. We tried doing logs, and running profiler and thats not catching it. We need a security expert who can figure out how this is happening and how to patch it up. This is a windows server written in asp
1) Complete and fully-functional working program(s) in executable form as well as complete source code of all work done.
2) Deliverables must be in ready-to-run condition, as follows? (depending on the nature? of the deliverables):
a)? For web sites or? other server-side deliverables intended to only ever exist in one place in the Buyer's environment--Deliverables must be installed by the Seller in ready-to-run condition in the Buyer's environment.
b) For all others including desktop software or software the buyer intends to distribute: A software? installation package that will install the software in ready-to-run condition on the platform(s) specified in this bid request.
3) All deliverables will be considered "work made for hire" under U.S. Copyright law. Buyer will receive exclusive and complete copyrights to all work purchased. (No GPL, GNU, 3rd party components, etc. unless all copyright ramifications are explained AND AGREED TO by the buyer on the site per the coder's Seller Legal Agreement).