Text Subsitution in a post
Discussion
.Mark said:
Had to try a post - most bizzare page I've ever seen!
Will put up a screen dump if theis doesn't fix it.
Didn't fix it check this out
[pic]
>> Edited by .Mark on Monday 27th September 18:16
I fixed it through my posts now. I tried only to edit the offending bits, but the "Reply" button was missing in the edit view. I deleted them then
Here's a conservated view:
(look, mine looks entirely different that yours, Mark?)
>> ahh, OK, this is because we view the topics in a different order!
>> Edited by Bodo on Monday 27th September 18:30
Tripps said:
Not really Ted, had enough recently fixing an application of mine against them - not fun
Drop me a line if you want some useful hints on picking these up - I've found some nice and simple solutions after much trial and error.
Firewalls aren't foolproof when it comes to SQL injection.
PetrolTed said:
Firewalls aren't foolproof when it comes to SQL injection.
Aye, but like anything else, the better firewalls stop the most.
Checkpoint FW-1 has specific SQL Injection detection and defeating, actually inspecting each packet and determining 'norty' content.
Nothing beats a perfect code, but a good FW will give you 99% more freedom 100% of the time.
No denying tho, the more methods you can implement to keep yourself safe ( Code / Software / Hardware) the better

PetrolTed said:
There are some very simple measures you can take which are good practice and alert you to all sorts of problems and hacking attempts. It took me several years to cotton on to them though!
Thats why try as you might in this industry, nothing can really touch experience. Something the kids dont seem to grasp

PetrolTed said:Cheers Ted,
Tripps said:Drop me a line if you want some useful hints on picking these up - I've found some nice and simple solutions after much trial and error.
Not really Ted, had enough recently fixing an application of mine against them - not fun
Might well give you a bell sometime.
We tend to follow best practice now after we had a case a few years back of a junior tester at a client trying to get himself a promotion by hacking apart a web application we were involved in, annoying at the time (days before my holiday) but we learn't a lot.
Its mostly the code I pick up with embedded SQL that suffers, re-implementing as sa stored procedure with lots of checks tends to make things better. Also do extensive client-side field filtering also seems to keep things happy.
Mind you there's always that last minute, burning the midnight oil code that perhaps isn't quite as safe

PetrolTed said:I know what you mean by a vacuum, I used to have a team at my desposal but now I'm working on me tod I find its easy to miss out on tricks and tips, must expand the company soon rather than waste money of buying a TVR!
Sounds like you've got it covered. I tend to code in a bit of a vacuum so sometime miss some obvious techniques used by others.

Gassing Station | Website Feedback | Top of Page | What's New | My Stuff





Let's attack Pistonheads.....