Solved

Trying to get "forgot password" to work

Posted on 2006-11-07
6
210 Views
Last Modified: 2012-08-14
Right now I have the code that is supposed to make this work, but it doesn't seem to find the right account holder in the db.  The secret question has an apostrophe in it so I have worked around that, but on this page where it pulls from the db, the code I have doesn't seem to work the same way.  I hope this isn't too confusing.  Below is my code:

'-----lost.asp

<%
Dim LostPassword

Set LostPassword = Server.CreateObject("ADODB.Connection")
ConnStr = "DRIVER={Microsoft Access Driver (*.mdb)};pwd=password;"
ConnStr = ConnStr & "DBQ=" & Server.MapPath("/dev/students.mdb")
LostPassword.Open(ConnStr)

SQLtemp = "SELECT * FROM tblAccess WHERE secret_question = '" & Replace(secret_question, "'", "''") & "' AND answer = '" & Request.Form("answer") & "' AND strEmail = '" & Request.Form("strEmail") & "'"

Set rs = LostPassword.Execute(SQLtemp)

If Request.Form("secret_question") = "" AND Request.Form("answer") = "" AND Request.Form("strEmail") = "" then
      Session("Message") = "<font face='Verdana, Arial, Helvetica' size='2' color='#008080'><b>Invalid Entry! </b></font><font face='Verdana, Arial, Helvetica' size='2' color='0000FF'>Please enter Question, Answer and E-Mail.</font>"
         Response.Redirect "/dev/forgot.asp"
      Response.End
End if

If Request.Form("secret_question") = "" then
      Session("Message") = "<font face='Verdana, Arial, Helvetica' size='2' color='#008080'><b>Invalid Entry! </b></font><font face='Verdana, Arial, Helvetica' size='2' color='0000FF'>Please select Secret Question.</font>"
         Response.Redirect "/dev/forgot.asp"
      Response.End
End if

If Request.Form("answer") = "" then
      Session("Message") = "<font face='Verdana, Arial, Helvetica' size='2' color='#008080'><b>Invalid Entry! </b></font><font face='Verdana, Arial, Helvetica' size='2' color='0000FF'>Please enter Answer.</font>"
         Response.Redirect "/dev/forgot.asp"
      Response.End
End if

If Request.Form("strEmail") = "" then
      Session("Message") = "<font face='Verdana, Arial, Helvetica' size='2' color='#008080'><b>Invalid Entry! </b></font><font face='Verdana, Arial, Helvetica' size='2' color='0000FF'>Please enter E-Mail Address.</font>"
      Response.Redirect "/dev/forgot.asp"
      Response.End
End if

If rs.eof then
      rs.Close
      LostPassword.Close
      set LostPassword = Nothing
      Session("Message") = "<b><font face='Verdana, Arial, Helvetica' size='2' color='FF0000'>Sorry! </font></b><font face='Verdana, Arial, Helvetica' size='2' color='0000FF'>No Matches Found.</font>"
      Response.Redirect "/dev/forgot.asp"
      Response.End
end if

while not rs.eof


If Request.Form("secret_question") = rs("secret_question") AND Request.Form("answer") = rs("answer") AND Request.Form("strEmail") = rs("strEmail") Then

      dim Your_Email
      Your_Email = rs("strEmail")
      dim Date_In
      Date_In = rs("Entry_Date")
      dim secret_question
      secret_question = rs("secret_question")

      Response.Cookies("strEmail") = Your_Email
      Response.Cookies("still") = Date_In

      Session.TimeOut = 20
      Session("strEmail") = "Yes"

      Response.Redirect "/dev/profile.asp?UserLoggedIn=" & Your_Email
      Response.End
Else
      Session("Message") = "<font face='Verdana, Arial, Helvetica' size='2' color='FF0000'>Incorrect Answer or E-Mail Address.</font></p>"
      Response.redirect("/dev/forgot.asp")
      Response.End
End If
   rs.MoveNext
Wend

rs.Close
LostPassword.Close
set LostPassword = Nothing

%>
0
Comment
Question by:pingeyeg
  • 3
  • 2
6 Comments
 
LVL 25

Expert Comment

by:kevp75
ID: 17890483
you mention that the secret question has an apostrophe in it, but have worked around that.  Please clarify what you mean.  Did you go into the field in the database and replace it with something, are you doing this code wise?, etc...

My first guess would be that you changed it in the table, but are trying to put it in your form field for your secret question.

BTW, the single quote/apostrophe is the biggest cause of the SQL Injection attack.
0
 
LVL 1

Author Comment

by:pingeyeg
ID: 17890541
Basically what I did was when a user edits their account and makes a secret question and answer, I had the sql statement replace the ' with ''.  That way it would work.  Well now I am trying to pull that information and I believe the sql statment doesn't like the single quote in the db.  I am trying to work around that on this page.  How can I do that.
0
 
LVL 25

Expert Comment

by:kevp75
ID: 17890658
it doesn't like the single quote, because that is something that is used to escape the SQL statement.  Hence why you replace it with ''
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 1

Author Comment

by:pingeyeg
ID: 17890677
Where on this page can I place a Replace statement to replace the ' with ''?
0
 
LVL 6

Accepted Solution

by:
gete earned 500 total points
ID: 17890750
If that's the exact actual code, I think you didn't escape the intended variables. Try to modify:

SQLtemp = "SELECT * FROM tblAccess WHERE secret_question = '" & Replace(secret_question, "'", "''") & "' AND answer = '" & Request.Form("answer") & "' AND strEmail = '" & Request.Form("strEmail") & "'"

to:

SQLtemp = "SELECT * FROM tblAccess WHERE secret_question = '" & Replace(Request.Form("secret_question"), "'", "''") & "' AND answer = '" & Request.Form("answer") & "' AND strEmail = '" & Request.Form("strEmail") & "'"

As kevp75 mentioned, you need to be careful of injection in crafting inline SQL statement, i.e. you need to also escape answer and strEmail:

SQLtemp = "SELECT * FROM tblAccess WHERE secret_question = '" & Replace(Request.Form("secret_question"), "'", "''") & "' AND answer = '" & Replace(Request.Form("answer"), "'", "''") & "' AND strEmail = '" & Replace(Request.Form("strEmail"), "'", "''") & "'"

Another thing, although this comparison seems redundant due to the similarity to the SQL WHERE condition:
If Request.Form("secret_question") = rs("secret_question") AND Request.Form("answer") = rs("answer") AND Request.Form("strEmail") = rs("strEmail") Then

it can give you different result, i.e. although it passes the SQL statement (gives you Recordset), the ASP/VBScript comparison doesn't compute it as True. This is because SQL in many DBMS is case insensitive while string comparison in ASP/VBScript is case sensitive. If you want it to be case sensitive, then the ASP/VBScript code will help. If not, you can drop the ASP/VBScript comparison since the SQL already takes care of it.
0
 
LVL 25

Expert Comment

by:kevp75
ID: 17891203
your welcome, glad I could help :|
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Have you ever needed to get an ASP script to wait for a while? I have, just to let something else happen. Or in my case, to allow other stuff to happen while I was murdering my MySQL database with an update. The Original Issue This was written…
I was asked about the differences between classic ASP and ASP.NET, so let me put them down here, for reference: Let's make the introductions... Classic ASP was launched by Microsoft in 1998 and dynamically generate web pages upon user interact…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now