- Feature Articles
- CodeSOD
- Error'd
- Forums
-
Other Articles
- Random Article
- Other Series
- Alex's Soapbox
- Announcements
- Best of…
- Best of Email
- Best of the Sidebar
- Bring Your Own Code
- Coded Smorgasbord
- Mandatory Fun Day
- Off Topic
- Representative Line
- News Roundup
- Editor's Soapbox
- Software on the Rocks
- Souvenir Potpourri
- Sponsor Post
- Tales from the Interview
- The Daily WTF: Live
- Virtudyne
Admin
mmmmmmmmm. malicious code in the query string.
Admin
There you go. (written for SqlServer using C# or ASP.NET, but I'm sure you can figure out something similar elsewhere.)
And I'm not even paid to write SQL or any other programs, yet I know the above and have verified that it works. Gads I need a programming job...
Admin
'); DELETE FROM Articles; --
Admin
Oracle needs them SQL Server doesn't
Admin
mea culpa, mea maxima culpa.
I was a bit too fast, indeed. But it still wouldn't allow a sentence like "Did God create the universe?"
Admin
"We goan' drop the bomb on the concert next week with this whoopin' tune I got."
Captcha: minim
Admin
It will not protect you from "delete/%20/%20from%20tbl_tablename"
because you are detecting "delete%20"
Admin
Poor Valter Borges...
Admin
Would you prefer it if we INSERTed LOLCats?
Admin
It's important to pay attention to these detials.
Admin
') DELETE FROM Articles --
<.<
Did it work?
Admin
hack this http://hub.iibn.info pleaseeeeeee