Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 Bug fix in active
 New Topic  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

modifichicci
Average Member

Italy
787 Posts

Posted - 12 December 2007 :  13:32:07  Show Profile  Visit modifichicci's Homepage
What is the right code now?

lastDate = Request.Form("BuildTime")

or

lastDate = ChkString(Request.Form("BuildTime"),"SQLString")

as the last post by Ruirib
http://forum.snitz.com/forum/topic.asp?whichpage=1&TOPIC_ID=66003#371472

Ernia e Laparocele
Forum di Ernia e Laparocele
Acces - MySql Migration Tutorial
Adamantine forum

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 12 December 2007 :  13:36:03  Show Profile  Send ruirib a Yahoo! Message
You cannot put things in that way. You either use the first fix posted, which will work and protect you or the last one, which will also protect you. The last one is a bit more restrictive, since it forces the value input through the form to be a number and if it isn't, it just uses the forum time instead.

What you cannot do is to remove a single line from the fix and ask if that line is correct. Each of the fixes works as whole.

Personally, I prefer the last fix, since it's more restrictive, but both will protect from SQL Injection.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

AnonJr
Moderator

United States
5768 Posts

Posted - 12 December 2007 :  13:37:33  Show Profile  Visit AnonJr's Homepage
I would imagine the last post that Ruirib made. While the latest addition isn't strictly necessary, it makes sense to keep people from injecting bad data into the field. If I remember right it was updated to account for people who were trying the hack on a patched forum. The attempted hack did put some invalid data in the field, but did not "hack" the forum.

Edit: I guess if I'd have just waited one more second the answer would have been there already.

Edited by - AnonJr on 12 December 2007 13:38:36
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 12 December 2007 :  13:40:39  Show Profile  Send ruirib a Yahoo! Message
I edited the last post for the bug fix to make it more clear.

Mark, thanks for explaining anyway .


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

modifichicci
Average Member

Italy
787 Posts

Posted - 12 December 2007 :  13:41:41  Show Profile  Visit modifichicci's Homepage
Yes I understand now, my doubt was if that was an add to the fix or an alternative, now I know it is an alternative.

What of them will be on next snitz version, if you know that?

Ernia e Laparocele
Forum di Ernia e Laparocele
Acces - MySql Migration Tutorial
Adamantine forum
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 12 December 2007 :  13:43:26  Show Profile  Send ruirib a Yahoo! Message
I would vote for the 2nd. Davio already added the first one to 3.4.07, but I will propose that he adds the 2nd, since the overall behavior is better.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

modifichicci
Average Member

Italy
787 Posts

Posted - 12 December 2007 :  13:45:02  Show Profile  Visit modifichicci's Homepage
Thanks

Ernia e Laparocele
Forum di Ernia e Laparocele
Acces - MySql Migration Tutorial
Adamantine forum
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.7 seconds. Powered By: Snitz Forums 2000 Version 3.4.07