September 22 2024 08:46:59
News Photos Forum Search Contact History Linkbox Calendar
 
Forum Threads
Newest Threads
AI discussion
Starship orbital lau...
Covers that Rock
The Tech billionaire...
Covers that never sh...
Besti ella størsti ...
Good music that peop...
UFO incidents
Great live performances
Guitar playing on Yo...
Linkbox
Newest Links
Another reason Rings... (0)
Meet Your Second Wife (1)
Why this neurosurgeo... (0)
Helm's Deep not a su... (0)
The Rings Of Power S... (0)
The Starliner spacec... (0)
"Interpolating" songs.. (0)
Richard Dawkins face... (1)
The Deadliest City o... (0)
74 year old sit down... (0)
Random Photo


Høgni's pictures from 62 year birthday

Member Poll
Should I watch "The Rings of Power"?

Yes

No

LOL

You must login to vote.
Link
 CategoryLink
Rating
funAn interesting SQL injection strategy
-4

Comments
Laluu on March 22 2010 23:04:58
Looking at the + and - columns, I'm guessing that this is hilarious, but we just don't get it. smiley
OKJones on March 22 2010 23:18:44
Or it's not hilarious and we don't get it. smiley

Or the minus is used as a blank vote smiley
Grizlas on March 23 2010 00:34:18
Well, maybe some explanation is in order; an SQL injection is basically someone trying to gain access to a SQL database via user input fields, such as this comment box I'm writing in at the moment. If user input is accepted as is and inserted in the database directly, you might allow a user to write some espace characters like \\\\\\\ wich escape the last character entered, and then eventually being able to execute some command that destroy the database, or make the hacker admin or some such undesirable thing.

In this case, the intention seems to be to hack traffic cameras smiley

(which is not to be taken seriously)
Vuzman on March 23 2010 15:21:52
A semi-colon ends an SQL statement. Now, if I enter something with a semi-colon into, say the shout box, and this is saved straight to the database (which it would be if it wasn't coded very well), then the database would stop saving the shout at the semi-colon, and presume that whatever came next was an actual SQL statement.

If that was, say 'DROP DATABASE gongumenn', and I guessed the database name correct, then the entire site would vanish in a puff of smoke.

'Tablice' is Polish for 'license plate'.
Post Comment
Please Login to Post a Comment.
Login
Username

Password



Forgotten your password?
Request a new one here.
Last Seen Users
Torellion07:04:54
Norlander19:34:16
Grizlas 1 day
OKJones 1 day
Vuzman 1 day
Boddin 2 days
Spiff 2 weeks
fjallsbak 3 weeks
Laluu 5 weeks
Anubis_fo 9 weeks
Obituaries
You must login to post a message.

Vuzman
26/08/2024 07:45
Try the google search box

Grizlas
24/08/2024 23:30
doubtful

OKJones
24/08/2024 22:08
does the search function even work?

Grizlas
24/12/2023 15:06
Gleðilig jól

Norlander
24/12/2023 10:09
Gleðilig jól!

Norlander
29/10/2023 19:16
:/

Grizlas
29/10/2023 11:35
RIP Matthew Perry.

Norlander
25/08/2023 19:22
That's not from the chess scene, it's Omar to Wee Bay, 2 mins into this clip: https://www.youtube.com/w
atch?v=LF0Xt6b525E


Vuzman
25/08/2023 18:11
That chess scene is forever seared into my memory...

Norlander
24/08/2023 20:03
You quoting the Wire, wow smiley