Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Snitz Forums 2000 DEV-Group
 DEV Internationalization (v4-archive)
 Bug(?) after latest Security Patch (post_info.asp)
 New Topic
 Printer Friendly
Author Previous Topic Topic Next Topic  

Esoterica.gr
Starting Member

Greece
43 Posts

Posted - 16 June 2002 :  18:45:10  Show Profile  Visit Esoterica.gr's Homepage  Reply with Quote
I have send the same message on the topic http://forum.snitz.com/forum/topic.asp?whichpage=2&TOPIC_ID=28511 (v33(.0x) BUG + FIX: post.asp & post_info.asp, DEV Bug Reports (Open) Forum). I'll post it here too because it may be an internationalization specific one (I'm not sure).

So here is the problem;

We have the following problem after installing the Bug Fixes that are proposed in post.asp & post_info.asp

- Some of the member's passwords aren't strictly alphanumeric and when they try to post a message (they are logged in succesfully off-cource) they get an error message about invalid password.
- Another problem is of infinite loops after a succesful posting; the congratulations message keeps swowing on and on.

Thanks in advance for any help on this!


[moved by bozden on 02 October 2002]

<

Edited by - Deleted on 02 October 2002 22:06:12

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 16 June 2002 :  18:49:09  Show Profile  Send ruirib a Yahoo! Message
It only makes sense to post it in a single forum. And I would find quite unlikely to have a bug specific to v 4.0 (although possible), since Bozden does nothing else than to apply the fixes posted for the non International version.

-------------------------------------------------
Installation Guide | Do's and Dont's | MODs
<
Go to Top of Page

Esoterica.gr
Starting Member

Greece
43 Posts

Posted - 16 June 2002 :  19:30:47  Show Profile  Visit Esoterica.gr's Homepage
Ok, thanks for the correction and you may delete this topic if you find it's not on the correct forum. Anyway I posted the situation here too because I have the suspicion that the problem maybe connected with the use of greek characters or special symbols in the passwords. It might seem probable that the altered post.asp and post_info.asp misinterpret these characters as a malicious attempt... Maybe the problem is related only to non-English environments in which the user can use non standard characters?

<
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 16 June 2002 :  19:51:31  Show Profile  Send ruirib a Yahoo! Message
quote:

Ok, thanks for the correction and you may delete this topic if you find it's not on the correct forum. Anyway I posted the situation here too because I have the suspicion that the problem maybe connected with the use of greek characters or special symbols in the passwords. It might seem probable that the altered post.asp and post_info.asp misinterpret these characters as a malicious attempt... Maybe the problem is related only to non-English environments in which the user can use non standard characters?


No problem with your post. Bump the message in the other thread, to see if someone from the Dev team can help you with it.

And frankly I would not encourage the use of non-standard characters for the password, but this is just my own opinion. I have a site in Portuguese (we have some "strange" chars also) and I do not allow using those chars for passwords. It can avoid some problems.

To tell ya the truth, I haven't looked very attentively to the fixes in post.asp and post_info.asp, so I can't even discuss their possible impact on your problem.

Bump your other topic. Bozden is going on vacation soon it's kind unlikely that he can have a look at this anyway. But I think this should be addressed by the Dev team...

-------------------------------------------------
Installation Guide | Do's and Dont's | MODs
<
Go to Top of Page

Esoterica.gr
Starting Member

Greece
43 Posts

Posted - 16 June 2002 :  20:15:16  Show Profile  Visit Esoterica.gr's Homepage
Nice, thanks again, I'll do what you suggested!

<
Go to Top of Page

Deleted
deleted

4116 Posts

Posted - 17 June 2002 :  06:22:12  Show Profile
But, native chars will be more secure.

Esoterica.gr, did you upgrade your database to Access 2000 after these people register? The problem can be because of the Unicode conversion problem.

Can you do this test?

Create two test users and use all possible chars in your alphabet (divide the alphabet into two because the field size is limited). If they can subscribe, then it is NOT these special chars. If errors come out, can you try to localize the problematic chars?

=====================================================================

Infinite loops are addressed here before (search w. keywords "endless refresh") and that will be solved with with v3.4 as far as I know.


Think Pink
==> Start Internationalization Here<
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 17 June 2002 :  06:44:36  Show Profile  Send ruirib a Yahoo! Message
quote:

But, native chars will be more secure.
Think Pink
==> Start Internationalization Here


You mean, more secure because there will be more possibilities to test if someone tries to find the password by brute force methods?

-------------------------------------------------
Installation Guide | Do's and Dont's | MODs
<
Go to Top of Page

Deleted
deleted

4116 Posts

Posted - 17 June 2002 :  09:46:18  Show Profile
Yep . Also somebody with another keyboard layout cannot enter directly...


Think Pink
==> Start Internationalization Here<
Go to Top of Page

Esoterica.gr
Starting Member

Greece
43 Posts

Posted - 18 June 2002 :  02:25:31  Show Profile  Visit Esoterica.gr's Homepage
I'm running the tests and I'll keep you informed whenever I get something meaningful.

Thanks a lot for the help!

<
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.16 seconds. Powered By: Snitz Forums 2000 Version 3.4.07