Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

Coding Forum


You are currently viewing our Coding Forum as a guest. Please register to participate.
Login



Reply
Sounds stupid, but can you help anyways?
Old 06-15-2007, 03:35 AM Sounds stupid, but can you help anyways?
The PHP Professor

Posts: 340
Name: Alex
Location: Behind You
Trades: 0
This question might strike some of you as odd, but i really need to know the answer. I just put my website up and i was wondering if anybody could try MySQL injection on it, well not really try, but is it possible? I have trimmed all whitespace and escaped all quotes, and limited characters for the login, am i missing anything?

Take a stop by 1Stopupload.com and see if its possible to do damage?!


Oh and i know this sounds like an invitation for hackers, so i have decided to put a IP tracker and an IP banning system, along with a system log that logs all actions, so i am not afraid, plus i have my database backed up every 24hrs.(If you think its a lie, try getting away with uploading porn!)


Thanks in advance all!
__________________
Go Kirby! <(" . "<) (^" . "^) (>" . ")> Talkupation!
microcolt is offline
Reply With Quote
View Public Profile Visit microcolt's homepage!
 
 
Register now for full access!
Old 06-15-2007, 04:02 AM Re: Sounds stupid, but can you help anyways?
JeremyMiller's Avatar
WT Moderator

Posts: 1,712
Name: Jeremy Miller
Location: Las Vegas, NV
Trades: 0
I just wrote a tutorial on protection of SQL injection in PHP at programmerstalk.net/thread722.html which addresses wildcards in queries containing LIKE .
__________________
Jeremy Miller

Please login or register to view this content. Registration is FREE
JeremyMiller is offline
Reply With Quote
View Public Profile Visit JeremyMiller's homepage!
 
Old 06-15-2007, 04:13 AM Re: Sounds stupid, but can you help anyways?
The PHP Professor

Posts: 340
Name: Alex
Location: Behind You
Trades: 0
i dont have any LIKE queries.
__________________
Go Kirby! <(" . "<) (^" . "^) (>" . ")> Talkupation!
microcolt is offline
Reply With Quote
View Public Profile Visit microcolt's homepage!
 
Old 06-15-2007, 04:15 AM Re: Sounds stupid, but can you help anyways?
JeremyMiller's Avatar
WT Moderator

Posts: 1,712
Name: Jeremy Miller
Location: Las Vegas, NV
Trades: 0
OK. I use them when doing login queries for the username for case insensitivity in the username while being able to preserve the casing that was intended by the end user when they created their account (e.g. display as JeremyMiller, but could login as jeremymiller or JeremyMiller)
__________________
Jeremy Miller

Please login or register to view this content. Registration is FREE
JeremyMiller is offline
Reply With Quote
View Public Profile Visit JeremyMiller's homepage!
 
Old 06-15-2007, 04:08 PM Re: Sounds stupid, but can you help anyways?
The PHP Professor

Posts: 340
Name: Alex
Location: Behind You
Trades: 0
oh, i understand what you are saying, yes i have a case sensitivity thing like that, but no it does not use the LIKE command. Thanks for the heads up!
__________________
Go Kirby! <(" . "<) (^" . "^) (>" . ")> Talkupation!
microcolt is offline
Reply With Quote
View Public Profile Visit microcolt's homepage!
 
Reply     « Reply to Sounds stupid, but can you help anyways?
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.28545 seconds with 12 queries