Solved

Trying to get "forgot password" to work

Posted on 2006-11-07
6
211 Views
Last Modified: 2012-08-14
Right now I have the code that is supposed to make this work, but it doesn't seem to find the right account holder in the db.  The secret question has an apostrophe in it so I have worked around that, but on this page where it pulls from the db, the code I have doesn't seem to work the same way.  I hope this isn't too confusing.  Below is my code:

'-----lost.asp

<%
Dim LostPassword

Set LostPassword = Server.CreateObject("ADODB.Connection")
ConnStr = "DRIVER={Microsoft Access Driver (*.mdb)};pwd=password;"
ConnStr = ConnStr & "DBQ=" & Server.MapPath("/dev/students.mdb")
LostPassword.Open(ConnStr)

SQLtemp = "SELECT * FROM tblAccess WHERE secret_question = '" & Replace(secret_question, "'", "''") & "' AND answer = '" & Request.Form("answer") & "' AND strEmail = '" & Request.Form("strEmail") & "'"

Set rs = LostPassword.Execute(SQLtemp)

If Request.Form("secret_question") = "" AND Request.Form("answer") = "" AND Request.Form("strEmail") = "" then
      Session("Message") = "<font face='Verdana, Arial, Helvetica' size='2' color='#008080'><b>Invalid Entry! </b></font><font face='Verdana, Arial, Helvetica' size='2' color='0000FF'>Please enter Question, Answer and E-Mail.</font>"
         Response.Redirect "/dev/forgot.asp"
      Response.End
End if

If Request.Form("secret_question") = "" then
      Session("Message") = "<font face='Verdana, Arial, Helvetica' size='2' color='#008080'><b>Invalid Entry! </b></font><font face='Verdana, Arial, Helvetica' size='2' color='0000FF'>Please select Secret Question.</font>"
         Response.Redirect "/dev/forgot.asp"
      Response.End
End if

If Request.Form("answer") = "" then
      Session("Message") = "<font face='Verdana, Arial, Helvetica' size='2' color='#008080'><b>Invalid Entry! </b></font><font face='Verdana, Arial, Helvetica' size='2' color='0000FF'>Please enter Answer.</font>"
         Response.Redirect "/dev/forgot.asp"
      Response.End
End if

If Request.Form("strEmail") = "" then
      Session("Message") = "<font face='Verdana, Arial, Helvetica' size='2' color='#008080'><b>Invalid Entry! </b></font><font face='Verdana, Arial, Helvetica' size='2' color='0000FF'>Please enter E-Mail Address.</font>"
      Response.Redirect "/dev/forgot.asp"
      Response.End
End if

If rs.eof then
      rs.Close
      LostPassword.Close
      set LostPassword = Nothing
      Session("Message") = "<b><font face='Verdana, Arial, Helvetica' size='2' color='FF0000'>Sorry! </font></b><font face='Verdana, Arial, Helvetica' size='2' color='0000FF'>No Matches Found.</font>"
      Response.Redirect "/dev/forgot.asp"
      Response.End
end if

while not rs.eof


If Request.Form("secret_question") = rs("secret_question") AND Request.Form("answer") = rs("answer") AND Request.Form("strEmail") = rs("strEmail") Then

      dim Your_Email
      Your_Email = rs("strEmail")
      dim Date_In
      Date_In = rs("Entry_Date")
      dim secret_question
      secret_question = rs("secret_question")

      Response.Cookies("strEmail") = Your_Email
      Response.Cookies("still") = Date_In

      Session.TimeOut = 20
      Session("strEmail") = "Yes"

      Response.Redirect "/dev/profile.asp?UserLoggedIn=" & Your_Email
      Response.End
Else
      Session("Message") = "<font face='Verdana, Arial, Helvetica' size='2' color='FF0000'>Incorrect Answer or E-Mail Address.</font></p>"
      Response.redirect("/dev/forgot.asp")
      Response.End
End If
   rs.MoveNext
Wend

rs.Close
LostPassword.Close
set LostPassword = Nothing

%>
0
Comment
Question by:pingeyeg
  • 3
  • 2
6 Comments
 
LVL 25

Expert Comment

by:kevp75
ID: 17890483
you mention that the secret question has an apostrophe in it, but have worked around that.  Please clarify what you mean.  Did you go into the field in the database and replace it with something, are you doing this code wise?, etc...

My first guess would be that you changed it in the table, but are trying to put it in your form field for your secret question.

BTW, the single quote/apostrophe is the biggest cause of the SQL Injection attack.
0
 
LVL 1

Author Comment

by:pingeyeg
ID: 17890541
Basically what I did was when a user edits their account and makes a secret question and answer, I had the sql statement replace the ' with ''.  That way it would work.  Well now I am trying to pull that information and I believe the sql statment doesn't like the single quote in the db.  I am trying to work around that on this page.  How can I do that.
0
 
LVL 25

Expert Comment

by:kevp75
ID: 17890658
it doesn't like the single quote, because that is something that is used to escape the SQL statement.  Hence why you replace it with ''
0
Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

 
LVL 1

Author Comment

by:pingeyeg
ID: 17890677
Where on this page can I place a Replace statement to replace the ' with ''?
0
 
LVL 6

Accepted Solution

by:
gete earned 500 total points
ID: 17890750
If that's the exact actual code, I think you didn't escape the intended variables. Try to modify:

SQLtemp = "SELECT * FROM tblAccess WHERE secret_question = '" & Replace(secret_question, "'", "''") & "' AND answer = '" & Request.Form("answer") & "' AND strEmail = '" & Request.Form("strEmail") & "'"

to:

SQLtemp = "SELECT * FROM tblAccess WHERE secret_question = '" & Replace(Request.Form("secret_question"), "'", "''") & "' AND answer = '" & Request.Form("answer") & "' AND strEmail = '" & Request.Form("strEmail") & "'"

As kevp75 mentioned, you need to be careful of injection in crafting inline SQL statement, i.e. you need to also escape answer and strEmail:

SQLtemp = "SELECT * FROM tblAccess WHERE secret_question = '" & Replace(Request.Form("secret_question"), "'", "''") & "' AND answer = '" & Replace(Request.Form("answer"), "'", "''") & "' AND strEmail = '" & Replace(Request.Form("strEmail"), "'", "''") & "'"

Another thing, although this comparison seems redundant due to the similarity to the SQL WHERE condition:
If Request.Form("secret_question") = rs("secret_question") AND Request.Form("answer") = rs("answer") AND Request.Form("strEmail") = rs("strEmail") Then

it can give you different result, i.e. although it passes the SQL statement (gives you Recordset), the ASP/VBScript comparison doesn't compute it as True. This is because SQL in many DBMS is case insensitive while string comparison in ASP/VBScript is case sensitive. If you want it to be case sensitive, then the ASP/VBScript code will help. If not, you can drop the ASP/VBScript comparison since the SQL already takes care of it.
0
 
LVL 25

Expert Comment

by:kevp75
ID: 17891203
your welcome, glad I could help :|
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Reading Date Settings from Server 6 59
Can not run ASP pages Windows 10 Edge browser. 5 73
Microsoft SQL ADO Conn Issue 6 37
Error in query expression 3 30
I recently decide that I needed a way to make my pages scream on the net.   While searching around how I can accomplish this I stumbled across a great article that stated "minimize the server requests." I got to thinking, hey, I use more than one…
I would like to start this tip/trick by saying Thank You, to all who said that this could not be done, as it forced me to make sure that it could be accomplished. :) To start, I want to make sure everyone understands the importance of utilizing p…
A short film showing how OnPage and Connectwise integration works.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

948 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now