Solved

asp2mysql preventing code injections

Posted on 2008-06-17
7
183 Views
Last Modified: 2010-03-19
normaly when i insert users text into varchar\text field the system will
show me an error if the user typed " or '...

so, how can i let enable those + prevent from hackers to inject some queries and codes...

?
10q
0
Comment
Question by:Forrest_Gump
7 Comments
 
LVL 82

Accepted Solution

by:
hielo earned 200 total points
ID: 21806833
>>show me an error if the user typed " or '...
You need to escape the apostrophes with back-to-back apostphes.
Assuming you have:
firstname=Replace(Request("firstname"),"'","''")
lastname=Replace(Request("lastname"),"'","''")
strSQL = "INSERT INTO users(firstname,lastname) VALUES('" & firstname & "','" & lastname & "' )"

 As for the double quotes, you shoud be enclosing the values of your fields with apostrophes, NOT double quotes.
So, it should NOT be:
...values("John","Smith")

it should be
...values('John','Smith')

and the previous step about replacing the apostrophes with back-to-back apostrophes should avoid an invalid statement.
0
 

Author Comment

by:Forrest_Gump
ID: 21807121
so what you say is that i need to do Replace(Request("lastname"),"'","''")
to every one of my fields?
0
 
LVL 82

Expert Comment

by:hielo
ID: 21807139
>>...to every one of my fields?
Yes, For every field that you intend to put INTO a db.
0
Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

 
LVL 29

Assisted Solution

by:rdivilbiss
rdivilbiss earned 150 total points
ID: 21809276
Actually there is a much better way.  Using prepared statements will prevent most SQL injections and allow you to ignore the issue of escaping quotes.

This also means when you return data from the database you also do not need to worry about un-escaping quotes.

Take a look at the attached link:

http://www.rodsdot.com/ee/parameterized_sql_multi_parameter.asp

You'll need to tweak a little for mySQL.
0
 
LVL 12

Assisted Solution

by:R_Harrison
R_Harrison earned 150 total points
ID: 21812763
Using two single quote, as Hielo suggest will only insert 1 single quote into the database, which is as per the user inputted and in my personal experience is the best way to go.

It should also be pointed out that SQL works equally well if you use numbers, in fact it is much easier to do SQL Injection if the page is expecting numbers as you do not usually have to escape the string.  Therefore if you are using numeric values in any SQL query then always check the value is actually numeric - don't assume it is just because that is what you are expecting...

e.g
if isNumeric(yourvariable)=false then -- do not run the SQL query as it could contain injection code --

0
 
LVL 29

Assisted Solution

by:rdivilbiss
rdivilbiss earned 150 total points
ID: 21813673
User input validation often fails victim to encoding attacks.

Using prepared statement or parameterized SQL is the strongest protection at little cost.

0
 
LVL 29

Expert Comment

by:rdivilbiss
ID: 21837962
Thanks for the assist and good luck on your project.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Get to know the ins and outs of building a web-based ERP system for your enterprise. Development timeline, technology, and costs outlined.
This article shows the steps required to install WordPress on Azure. Web Apps, Mobile Apps, API Apps, or Functions, in Azure all these run in an App Service plan. WordPress is no exception and requires an App Service Plan and Database to install
This tutorial demonstrates how to identify and create boundary or building outlines in Google Maps. In this example, I outline the boundaries of an enclosed skatepark within a community park.  Login to your Google Account, then  Google for "Google M…
The viewer will get a basic understanding of what section 508 compliance can entail, learn about skip navigation links, alt text, transcripts, and font size controls.

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question