Site Reviews
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsWeb DesignSite Reviews

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old April 6th, 2006, 06:20 AM
zeid zeid is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Apr 2006
Posts: 57 zeid User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 11 h 18 m 15 sec
Reputation Power: 3
Search engine project

Hello, I would appriciate any review about my internet search engine project, I know its simple (or you can call it poor) but it has a purpose.

http://www32.brinkster.com/zeidnetwork/index.asp
or
http://www.zeid.tk



Thanks in advance
zeid

Reply With Quote
  #2  
Old April 6th, 2006, 06:41 AM
LozWare's Avatar
LozWare LozWare is offline
Contributing User
ASP Free Novice (500 - 999 posts)
 
Join Date: Jun 2005
Posts: 531 LozWare User rank is Sergeant Major (2000 - 5000 Reputation Level)LozWare User rank is Sergeant Major (2000 - 5000 Reputation Level)LozWare User rank is Sergeant Major (2000 - 5000 Reputation Level)LozWare User rank is Sergeant Major (2000 - 5000 Reputation Level)LozWare User rank is Sergeant Major (2000 - 5000 Reputation Level)LozWare User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 4 Days 10 h 56 m 31 sec
Reputation Power: 46
Send a message via MSN to LozWare
http://www32.brinkster.com/zeidnetw...27hi%27%3D%27hi

Wow, you have 127 sites in your directory!

Jokes aside - what I am trying to say is that your site is SQL injectable. Its not much of an issue witha site like this - but I just thought that I would point it out.

Put it like this, the SQL injection that I used enabled me to look at all of the records in your database - big wow (im being sarcastic!).

However, if I knew the name of the table that you store all of the sites in, then I could type this into your search box:
Code:
'; DELETE * FROM tblSites;

And all of your sites would be gone. But like I said, I would have to guess the table name first.
__________________
LozWare Website Directory

Whooo! Free submissions, no recip needed. I'm a nice guy

Last edited by LozWare : April 6th, 2006 at 01:35 PM.

Reply With Quote
  #3  
Old April 6th, 2006, 07:26 AM
zeid zeid is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Apr 2006
Posts: 57 zeid User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 11 h 18 m 15 sec
Reputation Power: 3
Thank you for loosing time to check my site, can you please tell me how to get rid of these sql problems to make it secured.

Reply With Quote
  #4  
Old April 6th, 2006, 01:33 PM
LozWare's Avatar
LozWare LozWare is offline
Contributing User
ASP Free Novice (500 - 999 posts)
 
Join Date: Jun 2005
Posts: 531 LozWare User rank is Sergeant Major (2000 - 5000 Reputation Level)LozWare User rank is Sergeant Major (2000 - 5000 Reputation Level)LozWare User rank is Sergeant Major (2000 - 5000 Reputation Level)LozWare User rank is Sergeant Major (2000 - 5000 Reputation Level)LozWare User rank is Sergeant Major (2000 - 5000 Reputation Level)LozWare User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 4 Days 10 h 56 m 31 sec
Reputation Power: 46
Send a message via MSN to LozWare
Sure thing! Just put this on the page that processes the search...

Code:
Dim SearchString
SearchString = replace(request.form("TextField"),"'","")


You need to replace TextField with the name of the actaul field that the user writes the search query into. Then you just impliment the code into the project. The principal is simple: you are just deleting all of the vulnerable characters in the search term before it is executed in the SQL statement.

Reply With Quote
  #5  
Old April 6th, 2006, 03:42 PM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
ASP Free God 14th Plane (11500 - 11999 posts)
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 11,776 Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level) 
Time spent in forums: 3 Weeks 5 Days 8 h 27 m 42 sec
Reputation Power: 470
The application is also vulnerable to Cross Site Scripting attacks.

Example:
Enter the text below in your seach box
Code:
<script>alert('XXS Hackable');</script>

Reply With Quote
  #6  
Old April 6th, 2006, 05:46 PM
zeid zeid is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Apr 2006
Posts: 57 zeid User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 11 h 18 m 15 sec
Reputation Power: 3
thanks a lot
but what does it do "hack"???

Reply With Quote
  #7  
Old April 6th, 2006, 10:25 PM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
ASP Free God 14th Plane (11500 - 11999 posts)
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 11,776 Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level) 
Time spent in forums: 3 Weeks 5 Days 8 h 27 m 42 sec
Reputation Power: 470
Read up on what "Cross Site Scripting" is and can be used for, then you'll know why you need to prevent it.

Example:
I can inject HTML code into the page, I can inject javascript code into the page, etc...

Insert this into the search box and then look at what happens to your page as a result.
Code:
<table border='1'><td>First Name:</td><td><input type='text'></td></tr><tr><td>Last Name:</td><td><input type='text'></td></tr></table>

Last edited by Memnoch : April 6th, 2006 at 10:32 PM.

Reply With Quote
  #8  
Old April 7th, 2006, 05:21 AM
zeid zeid is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Apr 2006
Posts: 57 zeid User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 11 h 18 m 15 sec
Reputation Power: 3
Thanks very much for your time.

Reply With Quote
Reply

Viewing: ASP Free ForumsWeb DesignSite Reviews > Search engine project


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 5 hosted by Hostway
Stay green...Green IT