.NET Development
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsProgramming.NET Development

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #31  
Old April 30th, 2008, 02:10 PM
imbrod's Avatar
imbrod imbrod is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Jan 2006
Posts: 234 imbrod User rank is Sergeant (500 - 2000 Reputation Level)imbrod User rank is Sergeant (500 - 2000 Reputation Level)imbrod User rank is Sergeant (500 - 2000 Reputation Level)imbrod User rank is Sergeant (500 - 2000 Reputation Level)imbrod User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 16 h 53 m 7 sec
Reputation Power: 11
About the command
sqlCommandDB = New System.Data.SqlClient.SqlCommand("SELECT [name] FROM [Customer] WHERE [Username] = '" & txtUserName.Text & "' AND [Password] = '" & txtPassword.Text & "'")

Is it safe? Is it SQL-injection proof?
I mean, what happens if somebody enters single quote (') in txtUserName or txtPassword ?

The reason I ask is that I'm new to .NET (studying it for past several weeks) so I still find it difficult to know when there is something automated and when I should write my additional code...

In classic ASP, I used to wrap the variable with the function that will replace one quote with two single quotes:
Code:
Function nav(var)
	If InStr(var, "'") <> 0 Then var = Replace(var, "'", "''")
	nav = var
End Function


in ASP.NET should be something like this, if I'm not wrong:
Code:
Function nav(ByVal var As String) As String
        If InStr(var, "'") <> 0 Then var = Replace(var, "'", "''")
        Return var
End Function


So I ask: is that necessary?

Reply With Quote
  #32  
Old April 30th, 2008, 02:15 PM
magic30 magic30 is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Apr 2008
Posts: 18 magic30 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 3 h 45 m 25 sec
Reputation Power: 0
yeah the coding works.
i know how to do that. changing the text. having logout button will allow other people to sing in.

Reply With Quote
  #33  
Old April 30th, 2008, 03:29 PM
Wolffy's Avatar
Wolffy Wolffy is offline
Slaprentice of Wolves
ASP Free Beginner (1000 - 1499 posts)
 
Join Date: Aug 2007
Location: Mossville, IL
Posts: 1,467 Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level) 
Time spent in forums: 2 Weeks 2 Days 1 h 41 m 47 sec
Reputation Power: 519
imbod;
Please don't hijack someone else's thread.
__________________
Wolffy
------------------------
Opinions expressed are my own and do not necessity reflect those of any sane person. Any code provided is intended to be an example and is provided AS IS. Rework for your specific environment may be required. Void where prohibited by law. Not valid in California. Your mileage may vary. Not FDIC insured

Reply With Quote
  #34  
Old April 30th, 2008, 03:54 PM
Wolffy's Avatar
Wolffy Wolffy is offline
Slaprentice of Wolves
ASP Free Beginner (1000 - 1499 posts)
 
Join Date: Aug 2007
Location: Mossville, IL
Posts: 1,467 Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level)Wolffy User rank is Colonel (50000 - 60000 Reputation Level) 
Time spent in forums: 2 Weeks 2 Days 1 h 41 m 47 sec
Reputation Power: 519
So, the question is what then...how to have the Logon/Logoff button execute different events based on the state of the button? I don't fully understand what you are trying to do here? What does it mean, exactly, to allow other people to logon?

Reply With Quote
  #35  
Old April 30th, 2008, 05:22 PM
imbrod's Avatar
imbrod imbrod is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Jan 2006
Posts: 234 imbrod User rank is Sergeant (500 - 2000 Reputation Level)imbrod User rank is Sergeant (500 - 2000 Reputation Level)imbrod User rank is Sergeant (500 - 2000 Reputation Level)imbrod User rank is Sergeant (500 - 2000 Reputation Level)imbrod User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 16 h 53 m 7 sec
Reputation Power: 11
Quote:
Originally Posted by Wolffy
imbod;
Please don't hijack someone else's thread.


I didn't hijack.
I was reffering to the code you suggested to magic30 containing the line I mentioned:

Code:
sqlCommandDB = New System.Data.SqlClient.SqlCommand("SELECT [name] FROM [Customer] WHERE [Username] = '" & txtUserName.Text & "' AND [Password] = '" & txtPassword.Text & "'")


You posted that code in post #11. I just wanted to comment on it and asked a question regarding it.

Last edited by imbrod : April 30th, 2008 at 05:24 PM.

Reply With Quote
Reply

Viewing: ASP Free ForumsProgramming.NET Development > Getting the register/ login feature to work


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 3 hosted by Hostway