The Web Design Group

... Making the Web accessible to all.

Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topic
> sanitizing an html form
pulp-girl
post May 13 2008, 11:09 AM
Post #1





Group: Members
Posts: 2
Joined: 13-May 08
Member No.: 5,638



Our site was hit by a sql injection. I handle the front end side and would liek to know a simple wayto restrict characters on an html form and a search field. Any help would be great. Thank you!
User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
Darin McGrew
post May 13 2008, 11:40 AM
Post #2


WDG Member
********

Group: Root Admin
Posts: 8,365
Joined: 4-August 06
From: Mountain View, CA
Member No.: 3



No client-side script is going to protect you from SQL injection.
User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
pulp-girl
post May 14 2008, 09:26 AM
Post #3





Group: Members
Posts: 2
Joined: 13-May 08
Member No.: 5,638



ok... so is this something that can only be stopped on the sql databasE? I'm sorry i'm really new to all this and was told that the best way to avoid this was the edit my html forms and search fields...
:|
User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post
Brian Chandler
post May 14 2008, 11:08 AM
Post #4


Jocular coder
********

Group: Members
Posts: 2,460
Joined: 31-August 06
Member No.: 43



QUOTE(pulp-girl @ May 14 2008, 11:26 PM) *

ok... so is this something that can only be stopped on the sql databasE? I'm sorry i'm really new to all this and was told that the best way to avoid this was the edit my html forms and search fields...
:|


Then you were told very definitely wrong. This is a programming problem - and it's a well-known issue, so there should be lots of resources to help.
User is offlinePM
Go to the top of the page
Toggle Multi-post QuotingQuote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



- Lo-Fi Version Time is now: 24th April 2024 - 09:22 PM