Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

ASP code filter

Posted on 2008-06-15
5
Medium Priority
?
299 Views
Last Modified: 2008-08-22
i am after suggestions for a good piece of code/script/plugin for checking/cleaning text that a user can enter, to ensure there is no injection, or potentially unwanted entry.

i have an asp site that users can log into and update there profile information, i would like for them to be able to enter some html formatting rather than straight text only, however i need to ensure that they cant be malicious and inject anything.t
one solution i had was to give them a standard format, eg Leadtext, Bullet point 1, Bullet point 2, Bullet point 3, Bullet point 4, EndText. However his is little better than what i have now.

Any suggestions guys.
Points will be split amoungst all that offer good advise,
Please bear in mind that i am by no means an experianced programer.

Cheers
Andrew
0
Comment
Question by:Andrew Davis
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 6

Expert Comment

by:Dirar Abu Kteish
ID: 21791105
This is a free plugin that can be easily installed and has a lot of useful functions to work with string
http://www.chilkatsoft.com/refdoc/xCkStringRef.html

and example page

http://www.example-code.com/asp/aspstring.asp
0
 
LVL 18

Author Comment

by:Andrew Davis
ID: 21791452
Thanks for that dxz2 it looks like they have some interesting tools, however i had a look at the tool it appears to me that it can strip the HTML tags altogether, however i want the users to be able to use html but i need it checked to ensure there are no nasties in it, eg database injection

cheers
0
 
LVL 6

Accepted Solution

by:
Dirar Abu Kteish earned 1400 total points
ID: 21791502
check this url explaining how you can protect yourself from sql injections http://www.4guysfromrolla.com/webtech/061902-1.shtml.
0
 
LVL 15

Assisted Solution

by:dosth
dosth earned 600 total points
ID: 21791523
http://www.ariel.web.id/blog/2007/03/15/checking-refferer-prevent-html-form-hijacking/

also before saving the user input to database, check for any <script></script> tag, usally injections done with this tag. use instr function to check any <script> tags is there and tell the user to remove the tags

http://www.w3schools.com/Vbscript/func_instr.asp
0
 
LVL 15

Expert Comment

by:dosth
ID: 22287623
thanks
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Hello, all! I just recently started using Microsoft's IIS 7.5 within Windows 7, as I just downloaded and installed the 90 day trial of Windows 7. (Got to love Microsoft for allowing 90 days) The main reason for downloading and testing Windows 7 is t…
I would like to start this tip/trick by saying Thank You, to all who said that this could not be done, as it forced me to make sure that it could be accomplished. :) To start, I want to make sure everyone understands the importance of utilizing p…
This tutorial will teach you the special effect of super speed similar to the fictional character Wally West aka "The Flash" After Shake : http://www.videocopilot.net/presets/after_shake/ All lightning effects with instructions : http://www.mediaf…
In this video, Percona Solution Engineer Rick Golba discuss how (and why) you implement high availability in a database environment. To discuss how Percona Consulting can help with your design and architecture needs for your database and infrastr…

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question