Php Effective Anti Injection Script -> No symbol block

Page 2 of 4 FirstFirst 1234 LastLast
Results 16 to 30 of 52
  1. #16
    Valued Member omriz1 is offline
    MemberRank
    Dec 2005 Join Date
    129Posts

    Re: [Release] Php Effective Anti Injection Script -> No symbol block

    Thanks, Good Job :]
    Which files connecting to mssql/ODBC ?

  2. #17
    Valued Member andersonbk is offline
    MemberRank
    Oct 2006 Join Date
    HereLocation
    127Posts

    Re: [Release] Php Effective Anti Injection Script -> No symbol block

    thx you veri much

  3. #18
    Banned DarkMaster. is offline
    BannedRank
    Feb 2007 Join Date
    BulgariaLocation
    812Posts

    Re: [Release] Php Effective Anti Injection Script -> No symbol block

    ENG: Great 10/10 !
    BG: bravo 10/10 !

  4. #19
    Valued Member jim3481 is offline
    MemberRank
    Jul 2004 Join Date
    CaliforniaLocation
    122Posts

    Re: [Release] Php Effective Anti Injection Script -> No symbol block

    sorry my noob question but..

    where i paste this script?

  5. #20
    Account Upgraded | Title Enabled! GhostOne is offline
    MemberRank
    Mar 2007 Join Date
    SomeWhereLocation
    251Posts

    Re: [Release] Php Effective Anti Injection Script -> No symbol block

    good release , useful :))

  6. #21
    Valued Member anhnga is offline
    MemberRank
    Nov 2004 Join Date
    Ha Long City, Quang Ninh Province, Viet NamLocation
    122Posts

    Re: [Release] Php Effective Anti Injection Script -> No symbol block

    Yes, how to put this code, where to put in the file?
    One file or all file in web
    etc: Where to put in MuWeb8.......
    Thank!!!!!

  7. #22
    Member SlavOOn is offline
    MemberRank
    Oct 2005 Join Date
    77Posts

    Re: [Release] Php Effective Anti Injection Script -> No symbol block

    When need this SQL anti injection? All problems in ' - quotes and ; - symbol...

    Use:
    if (!get_magic_quotes_gpc()) {
    $... = addslashes($_POST['...']);
    } else {
    $... = $_POST['...'];
    }

  8. #23
    Member WiWaWa is offline
    MemberRank
    Sep 2006 Join Date
    LithuaniaLocation
    60Posts

    Re: [Release] Php Effective Anti Injection Script -> No symbol block

    thx ;) Good job. :technolog

  9. #24
    Account Upgraded | Title Enabled! themad is offline
    MemberRank
    Dec 2004 Join Date
    BulgariaLocation
    1,018Posts

    Re: [Release] Php Effective Anti Injection Script -> No symbol block

    Quote Originally Posted by SlavOOn View Post
    When need this SQL anti injection? All problems in ' - quotes and ; - symbol...

    Use:
    You really should do some reading....
    The addslashes() is not a function to use for such a thing. Simply said:
    $charname=addslashes("Fluffy'; drop table character"); // you should get Fluffy\'; drop table character; -- right ? try to execute it and see what happens..
    mssql_query("select Resets from character where Name='".$charname."'");

    \' doesn't cut it with mssql...you have to use two single quotes in order to avoid it . Str_replace("'","'',$var);

    The script i have brough simply filters ALL user inputed variables from browser to server and checks not to double filter ( i mean the ' to become '''''..etc.. ), effective and without having to check every single post/get var..

    If you are using an addslashes() function as a protection..better change it fast..

  10. #25
    Valued Member anhnga is offline
    MemberRank
    Nov 2004 Join Date
    Ha Long City, Quang Ninh Province, Viet NamLocation
    122Posts

    Re: [Release] Php Effective Anti Injection Script -> No symbol block

    Quote Originally Posted by themad View Post
    You really should do some reading....
    The addslashes() is not a function to use for such a thing. Simply said:
    $charname=addslashes("Fluffy'; drop table character"); // you should get Fluffy\'; drop table character; -- right ? try to execute it and see what happens..
    mssql_query("select Resets from character where Name='".$charname."'");

    \' doesn't cut it with mssql...you have to use two single quotes in order to avoid it . Str_replace("'","'',$var);

    The script i have brough simply filters ALL user inputed variables from browser to server and checks not to double filter ( i mean the ' to become '''''..etc.. ), effective and without having to check every single post/get var..

    If you are using an addslashes() function as a protection..better change it fast..
    Themad!
    Please help me, how to add your script to muweb 08???, what file need to add....???
    Thank!

  11. #26
    Account Upgraded | Title Enabled! themad is offline
    MemberRank
    Dec 2004 Join Date
    BulgariaLocation
    1,018Posts

    Re: [Release] Php Effective Anti Injection Script -> No symbol block

    Quote Originally Posted by anhnga View Post
    Themad!
    Please help me, how to add your script to muweb 08???, what file need to add....???
    Thank!
    I have not downloaded muweb like..ever...i don't know how its build...can't help you

  12. #27
    Enthusiast eXtremee is offline
    MemberRank
    Sep 2005 Join Date
    Vilnius,LithuaniaLocation
    26Posts

    Re: [Release] Php Effective Anti Injection Script -> No symbol block

    Hmm,my site uses sql_inject.php , if i'll put this script in it,script would work?

  13. #28
    Valued Member forgetpass is offline
    MemberRank
    Oct 2004 Join Date
    104Posts

    Re: [Release] Php Effective Anti Injection Script -> No symbol block

    It is a nice script but it won't put an end to malicious attack. In MUweb ppl still could get their board hacked by remote inclusion, in a web of czf there's xss ... But the script does good enough to stop sql injection. wat i fear is blind sql injection -.-

  14. #29
    Member UnKn is offline
    MemberRank
    Feb 2007 Join Date
    91Posts

    Re: [Release] Php Effective Anti Injection Script -> No symbol block

    bug good man thx !!!

  15. #30
    Enthusiast favico is offline
    MemberRank
    Nov 2005 Join Date
    BrasilLocation
    48Posts

    Re: [Release] Php Effective Anti Injection Script -> No symbol block

    Nice.. thx man
    10/10
    Keep it Up!



Page 2 of 4 FirstFirst 1234 LastLast

Advertisement