SQL Inject fix

Page 2 of 2 FirstFirst 12
Results 16 to 27 of 27
  1. #16
    Developer / Patch Finder Tankado is offline
    MemberRank
    Oct 2011 Join Date
    The NetherlandsLocation
    451Posts

    Re: SQL Inject fix

    PenguinGuy, Money dominates and not everyone have time :)

  2. #17
    Praise the Sun! Solaire is offline
    MemberRank
    Dec 2007 Join Date
    Undead BurgLocation
    2,862Posts

    Re: SQL Inject fix

    Quote Originally Posted by SeaTroll View Post
    PenguinGuy, Money dominates and not everyone have time :)
    Yeah, that's obviously the reason, not the lack of knowledge.

  3. #18
    2D > 3D Wucas is offline
    MemberRank
    Dec 2008 Join Date
    In your bed :3Location
    2,523Posts

    Re: SQL Inject fix

    Quote Originally Posted by Wizkidje View Post
    Yeah, that's obviously the reason, not the lack of knowledge.
    But we are on Ragezone, knowledge and talent is everywhere the eye can see.

    @thread thanks for the fix

  4. #19
    Enthusiast isaias008 is offline
    MemberRank
    May 2011 Join Date
    37Posts

    Re: SQL Inject fix

    Quote Originally Posted by Wizkidje View Post
    Checking for ' only would suffice. Also, deleteclan, createcharacter, etc.

    SQL Inject fix ? Patch?

  5. #20
    Account Upgraded | Title Enabled! Wish Q is offline
    MemberRank
    Jul 2012 Join Date
    LiveScoreLocation
    456Posts

    Re: SQL Inject fix

    Quote Originally Posted by isaias008 View Post
    SQL Inject fix ? Patch?
    he means its not only deletecharacter.

  6. #21
    Enthusiast isaias008 is offline
    MemberRank
    May 2011 Join Date
    37Posts

    Re: SQL Inject fix

    More would have to protect the clan close?

  7. #22
    Wait wut PenguinGuy is offline
    MemberRank
    Apr 2010 Join Date
    United StatesLocation
    765Posts

    Re: SQL Inject fix

    Quote Originally Posted by Wizkidje View Post
    Oh, the irony.
    Ironic? .... What? I'm basically saying go make a game in its nature, as an example is Medal of Honor (newer ones) and BattleField BC 2. They each have their own different aspect, yet aiming on the same genre and fighting style. It's actually a terrible example, but one that should suffice.... Hopefully.

    @Wucas, knowledge is everywhere. Except here.

  8. #23
    Account Upgraded | Title Enabled! Wish Q is offline
    MemberRank
    Jul 2012 Join Date
    LiveScoreLocation
    456Posts

    Re: SQL Inject fix

    Quote Originally Posted by PenguinGuy View Post
    Ironic? .... What? I'm basically saying go make a game in its nature, as an example is Medal of Honor (newer ones) and BattleField BC 2. They each have their own different aspect, yet aiming on the same genre and fighting style. It's actually a terrible example, but one that should suffice.... Hopefully.

    @Wucas, knowledge is everywhere. Except here.
    So why are you not making it?

  9. #24
    Praise the Sun! Solaire is offline
    MemberRank
    Dec 2007 Join Date
    Undead BurgLocation
    2,862Posts

    Re: SQL Inject fix

    Quote Originally Posted by PenguinGuy View Post
    Ironic? .... What? I'm basically saying go make a game in its nature, as an example is Medal of Honor (newer ones) and BattleField BC 2. They each have their own different aspect, yet aiming on the same genre and fighting style. It's actually a terrible example, but one that should suffice.... Hopefully.

    @Wucas, knowledge is everywhere. Except here.
    The irony of someone in this GunZ community being able to even strip GunZ from the Realspace engine.

  10. #25
    Browser. Nova is offline
    MemberRank
    Nov 2008 Join Date
    --Location
    400Posts

    Re: SQL Inject fix

    Quote Originally Posted by Wish Q View Post
    why are there so many exploits in MMatchDBMgr?
    Because MMatchDBMgr is one of the classes (if not the only one) that works directly with the database, and it lacks basic integrity checks (like strip strings of ' ).

  11. #26
    Account Upgraded | Title Enabled! Wish Q is offline
    MemberRank
    Jul 2012 Join Date
    LiveScoreLocation
    456Posts

    Re: SQL Inject fix

    Quote Originally Posted by Nova View Post
    Because MMatchDBMgr is one of the classes (if not the only one) that works directly with the database, and it lacks basic integrity checks (like strip strings of ' ).
    thanks.

  12. #27
    Enthusiast mikisa33 is offline
    MemberRank
    Dec 2012 Join Date
    IsrealLocation
    47Posts

    Re: SQL Inject fix

    God job THX



Page 2 of 2 FirstFirst 12

Advertisement