[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

ASP Function Char replace issue

Posted on 2008-10-10
6
Medium Priority
?
968 Views
Last Modified: 2012-05-05
I am trying to stop SQL injection attacks.
I have written the following function that will help filter out the commands.
But i can't get it to output the VAR.

+ i'm not sure if how i'm going to use this funiction again and again for dirrent fields
from request.form().  like username and password.

But first things first.  Please can someone let me know why i can't get an output from the following:
<% 
function killChars(inputtext) 
			dim badChars 
			dim newChars 
			
			badChars = array("select", "drop", ";", "--", "insert", "delete", "xp_", "=") 
			newChars = inputtext 
			
			for i = 0 to uBound(badChars) 
			newChars = replace(newChars, badChars(i), "") 
			next 
			 response.write(inputtext & "done | ")
end function 
 
text1 = "Hello ' select bye"
 
call KillChars(text1)
response.write("CLEAN:" & newChars)
%>

Open in new window

0
Comment
Question by:myhc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 6

Expert Comment

by:RemcovC
ID: 22686181
You are using a var outside a function in which you declared it, that wont work

You could try something like this:

<%
function killChars(inputtext)
      dim badChars
                  
      badChars = array("select", "drop", ";", "--", "insert", "delete", "xp_", "=")
                  
      for i = 0 to uBound(badChars)
            killChars = replace(inputtext, badChars(i), "")
      next
      response.write(inputtext & "done | ")
end function
 
text1 = "Hello ' select bye"

response.write("CLEAN:" & KillChars(text1))
%>
0
 
LVL 3

Expert Comment

by:sam_norian
ID: 22686189
Hi,
 
 This uses a slightly different approach but should achieve the same result....

function killChars(inputtext)
    if not isNull(inputtext) then
        inputtext = Replace(inputtext,"select","")
        inputtext = Replace(inputtext,"drop","")
        inputtext = Replace(inputtext,"insert","")
        inputtext = Replace(inputtext,"delete","")
        inputtext = Replace(inputtext,"xp_","")
        inputtext = Replace(inputtext,"=","")
        inputtext = Replace(inputtext,"--","")
        inputtext = Replace(inputtext,";","")
        killChars = inputtext
     else
        inputtext = ""
     end if
end function
 
'''''''''''''To Call You Can Then Do..'''''''''''''''''''''''
 
killChars(request.form("YourField"))

Open in new window

0
 
LVL 6

Expert Comment

by:RemcovC
ID: 22686214
made a small error in the code....

<%
function killChars(inputtext)
      dim badChars
      killChars = inputtext          
      badChars = array("select", "drop", ";", "--", "insert", "delete", "xp_", "=")
                 
      for i = 0 to uBound(badChars)
            killChars = replace(killChars , badChars(i), "")
      next
      response.write(inputtext & "done | ")
end function
 
text1 = "Hello ' select bye"

response.write("CLEAN:" & KillChars(text1))
%>
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 7

Accepted Solution

by:
bluV11t earned 920 total points
ID: 22690678
<%
function killChars(inputtext)
                        dim badChars
                        dim newChars
                       
                        badChars = array("select", "drop", ";", "--", "insert", "delete", "xp_", "=")
                        newChars = inputtext
                       
                        for i = 0 to uBound(badChars)
                        newChars = replace(newChars, badChars(i), "")
                        next
                         response.write(inputtext & "done | ")
'THIS IS STEP1
killChars = inputtext

end function
 
text1 = "Hello ' select bye"
 
'THIS IS STEP2
myNewVariable = KillChars(text1)
response.write("CLEAN:" & myNewVariable )
%>
0
 
LVL 12

Assisted Solution

by:R_Harrison
R_Harrison earned 80 total points
ID: 22695342
By the way you also want to add single quote ' and colon : to you list of badChars, otherwise hackers will still be able to run SQL injection.

Also develop a second function for values that should be numeric (to ensure they are numeric) as these are the most vunerable to sql injection.    For you second function a simple isNumeric() should suffice.
0
 
LVL 7

Author Closing Comment

by:myhc
ID: 31504976
Sorted my code, works fine - Thank You
Harrison, Advised on more issues with SQL.
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have helped a lot of people on EE with their coding sources and have enjoyed near about every minute of it. Sometimes it can get a little tedious but it is always a challenge and the one thing that I always say is:   The Exchange of informatio…
This demonstration started out as a follow up to some recently posted questions on the subject of logging in: http://www.experts-exchange.com/Programming/Languages/Scripting/JavaScript/Q_28634665.html and http://www.experts-exchange.com/Programming/…
Have you created a query with information for a calendar? ... and then, abra-cadabra, the calendar is done?! I am going to show you how to make that happen. Visualize your data!  ... really see it To use the code to create a calendar from a q…
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question