Hello David, Thanks for the tips. I was able to correlate the timestamp of the error message and the bad guys IP address. The are using a POST to do the injection. -- Best regards, mikesz mailto:mikesz at qualityadvantages.com