CashTanker
Happy Investing, With Happy Christian Community
 
our advertising disclaimer | Disclaimer - Must be read before using forum or clicking any links
Moneycare.bz
imoneyreserve.com
BlockDOS.net - DDOS Protected Web Hosting!
The same protection that Talkgold Uses! Starting at $400/month when you mention Talkgold! The most reliable DDOS protection online!
Rating A**** 4,300 MEMBERs and growing - Cassie Johnson pays 12% Daily at iMoneyReserve.com
*** EXPRESS CashOut Daily - BONUS upto $1,200 - VIP Customer Support - 12% RefCom - Top Management and Admin ***
Put your banner or text ad in the rotation above!ONLY $17/day, $99/week, or $379/month!


Your Ad Here
Your Ad Here

above banners and links are advertisements only. We do not endorse or vouch for any advertisers.Put Your 728X90 Banner Here NOW!

Go Back   Talkgold HYIP, Investment & Money Forum > Caution : Risky High Yield Investing Programs > HYIP - AutoSurf Program Admin Talk
User Name
Password
Reply
 
Thread Tools Display Modes
  #1  
Old 06-16-2006, 07:04 AM
Test33's Avatar
Test33 Test33 is offline
Senior Investor
Join Date: Jan 2006
Location: Biggest Little City in the World
Posts: 609
Send a message via AIM to Test33 Send a message via MSN to Test33 Send a message via Yahoo to Test33
Default Re: SQL Injection - A simple way to prevent

Pretty much every script that connects to an SQL database without protection is vulnerable.
Reply With Quote
-- Sponsored Links --
  #2  
Old 06-16-2006, 08:15 AM
Test33's Avatar
Test33 Test33 is offline
Senior Investor
Join Date: Jan 2006
Location: Biggest Little City in the World
Posts: 609
Send a message via AIM to Test33 Send a message via MSN to Test33 Send a message via Yahoo to Test33
Default Re: SQL Injection - A simple way to prevent

Try to inject your own site. Google for some sample injections, that sql, I used up there was form wikipedia, so try them out. Most likely, as long as you add slashes to your queries, you should be fine. I myself, do not know how to bypass the slashes.
Reply With Quote
  #3  
Old 06-17-2006, 04:29 PM
iwe iwe is offline
Investor
Join Date: Jun 2005
Location: Indonesia
Posts: 138
Send a message via ICQ to iwe Send a message via MSN to iwe Send a message via Yahoo to iwe
Default Re: SQL Injection - A simple way to prevent

here is good solve for sql injection :
http://www.devsquare.org/php/22-sqli...n.html#post126

hope helps
Reply With Quote
  #4  
Old 06-17-2006, 05:48 PM
GoldScripts's Avatar
GoldScripts GoldScripts is offline
Amateur Investor
Join Date: May 2006
Posts: 95
Lightbulb Re: SQL Injection - A simple way to prevent

Read more about SQL injection here http://www.spidynamics.com/papers/SQ...WhitePaper.pdf
Reply With Quote
  #5  
Old 06-17-2006, 05:51 PM
GoldScripts's Avatar
GoldScripts GoldScripts is offline
Amateur Investor
Join Date: May 2006
Posts: 95
Post Re: SQL Injection - A simple way to prevent

Posted to help restrict the use of SQL queries in PHP applications.

function sql_quote($value)
{
if (get_magic_quotes_gpc())
{
$value = stripslashes( $value );
}
//check if this function exists
if (function_exists("mysql_real_escape_string"))
{
$value = mysql_real_escape_string($value);
}
//for PHP version < 4.3.0 or as a backup we use addslashes
else
{
$value = addslashes($value);
}
//return our final value based on which defense method we use above
return $value;
}
Reply With Quote
  #6  
Old 06-19-2006, 06:45 PM
Vicky23 Vicky23 is offline
Newbie Amateur
Join Date: Jun 2006
Posts: 6
Default Re: SQL Injection - A simple way to prevent

Intresting

Thanks
Reply With Quote
  #7  
Old 06-19-2006, 06:51 PM
Vicky23 Vicky23 is offline
Newbie Amateur
Join Date: Jun 2006
Posts: 6
Default Re: SQL Injection - A simple way to prevent

How does it work?

Thanks
Reply With Quote
  #8  
Old 06-19-2006, 11:13 PM
Test33's Avatar
Test33 Test33 is offline
Senior Investor
Join Date: Jan 2006
Location: Biggest Little City in the World
Posts: 609
Send a message via AIM to Test33 Send a message via MSN to Test33 Send a message via Yahoo to Test33
Default Re: SQL Injection - A simple way to prevent

The script adds slashes to the SQL injection query. For example, a'; drop users; this would drop the table users, which would delete all users. However, when you add slashes to it, it would look like: a\'; drop users. This adds the blackslash to the query either ending up with an sql error or returning false, depending on the script.

Hope that helps
Reply With Quote
  #9  
Old 06-21-2006, 11:35 PM
imer imer is offline
Newbie Amateur
Join Date: May 2006
Posts: 11
Default Re: SQL Injection - A simple way to prevent

Quote:
function sql_quote($value)
{
if (get_magic_quotes_gpc())
{
$value = stripslashes( $value );
}
//check if this function exists
if (function_exists("mysql_real_escape_string"))
{
$value = mysql_real_escape_string($value);
}
//for PHP version < 4.3.0 or as a backup we use addslashes
else
{
$value = addslashes($value);
}
//return our final value based on which defense method we use above
return $value;
}
where can I put this code? admin.php? index.php?

thanks..
Reply With Quote
  #10  
Old 06-21-2006, 11:43 PM
Test33's Avatar
Test33 Test33 is offline
Senior Investor
Join Date: Jan 2006
Location: Biggest Little City in the World
Posts: 609
Send a message via AIM to Test33 Send a message via MSN to Test33 Send a message via Yahoo to Test33
Default Re: SQL Injection - A simple way to prevent

I haven't looked into the admin.php, but it shouldn't matter. To make it neat and clean, I would make a new file call it sqlquote.php and include: include("sqlquote.php"); to your index.php and go to line 26ish, and put $query = sql_quote($query); then it should work.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


TALKGOLD
SIDEBAR ADS

ADVERTISE HERE. Must read: Advertising Terms & Disclaimer
PUT YOUR 120X120 AD HERE FOR ONLY $560/WEEK!
Click Here for details.
Your ad here! Cost of Ad - $550
Your ad here! Cost of Ad - $540
Your ad here! Cost of Ad - $530
Your ad here! Cost of Ad - $520
Your ad here! Cost of Ad - $510
Your ad here! Cost of Ad - $310
Your ad here! Cost of Ad - $230
Cost of Ad - $200
Your ad here! Cost of Ad - $190
Your Ad Here Cost of Ad - $120
Your Ad Here Cost of Ad - $120
Your ad here Cost of Ad - $105
Your ad here Cost of Ad - $105
Your ad here Cost of Ad - $105
Cost of Ad - $100
Your Ad Here Cost of Ad - $100
Instaforex Cost of Ad - $95
Your ad here! Cost of Ad - $80
Cost of Ad - $75
Your ad here Cost of Ad - $75
Your ad here Cost of Ad - $75
YOUR AD HERE

PUT YOUR NON-ROTATING AD HERE NOW!
ONLY $75/Week


click here
click here
YOUR AD HERE!
YOUR AD HERE!
Well Profit

1500% - 2000% After 1 Day, 3200% - 4200% After 2 Days

Only $39/week or $135/month - Advertise Now!
GENIUS PROFIT

250% After 10 Minutes (Instant Withdrawal)
800% After 3 Hour (Instant Withdrawal)
1400% After 10 Hour (Instant Withdrawal)
2500% After 24 Hour (Instant Withdrawal)
Www.Genius-Profit.Com
Only $39/week or $135/month - Advertise Now!
Check our Advertising Rates!

All times are GMT. The time now is 06:55 PM.

Add to Google

Protected by BlockDOS.net - DDOS Protection
Powered by: vBulletin - Copyright ©2000 - 2005, Jelsoft Enterprises Ltd.