Click here to Skip to main content
15,891,375 members
Home / Discussions / Database
   

Database

 
Questionrestore an in used SQL Database Pin
i-p-g-i5-Sep-05 22:41
i-p-g-i5-Sep-05 22:41 
AnswerRe: restore an in used SQL Database Pin
Frank Kerrigan5-Sep-05 22:57
Frank Kerrigan5-Sep-05 22:57 
AnswerRe: restore an in used SQL Database Pin
miah alom6-Sep-05 9:26
miah alom6-Sep-05 9:26 
Questiondatagrid titel ... Pin
Anonymous5-Sep-05 21:14
Anonymous5-Sep-05 21:14 
AnswerRe: datagrid titel ... Pin
Frank Kerrigan5-Sep-05 22:54
Frank Kerrigan5-Sep-05 22:54 
AnswerRe: datagrid titel ... Pin
miah alom6-Sep-05 8:19
miah alom6-Sep-05 8:19 
Questionw can User observe his private information Pin
mostafa_h5-Sep-05 10:22
mostafa_h5-Sep-05 10:22 
AnswerRe: w can User observe his private information Pin
Colin Angus Mackay5-Sep-05 20:53
Colin Angus Mackay5-Sep-05 20:53 
manije wrote:
strFilter = "SELECT UserName,Password FROM User_Name WHERE Password='" +txtPassword.Text + "' AND UserName='"+txtUserName.Text+"'";

This is NOT how I showed you to build this query[^]. This is now vulnerable to a SQL Injection Attack, and one that is very easily prevented. Please re-read the code I sent you before and if you don't understand it, I'll be happy to answer questions.

If you want to read more about how to prevent SQL Injection attacks. Something that is very important and double importance seing as this is verifying user names and passwords then you should read SQL Injection Attacks and Tips on How to Prevent Them[^]

Finally, just as an example of how easy your code is to attack I would suggest you type the following into the password box and trace through the code to see what it does:
' OR 1=1;--



My: Blog | Photos
WDevs.com - Open Source Code Hosting, Blogs, FTP, Mail and More


GeneralRe:I want to know how a user can observe Pin
mostafa_h6-Sep-05 1:57
mostafa_h6-Sep-05 1:57 
GeneralRe:I want to know how a user can observe Pin
Christian Graus6-Sep-05 11:51
protectorChristian Graus6-Sep-05 11:51 
QuestionConnection Via DSN in VB.Net Pin
MODI_RAHUL5-Sep-05 3:20
MODI_RAHUL5-Sep-05 3:20 
AnswerRe: Connection Via DSN in VB.Net Pin
Andy Brummer5-Sep-05 4:05
sitebuilderAndy Brummer5-Sep-05 4:05 
GeneralRe: Connection Via DSN in VB.Net Pin
miah alom6-Sep-05 9:44
miah alom6-Sep-05 9:44 
GeneralRe: Connection Via DSN in VB.Net Pin
Andy Brummer6-Sep-05 12:18
sitebuilderAndy Brummer6-Sep-05 12:18 
GeneralRe: Connection Via DSN in VB.Net Pin
Anonymous7-Sep-05 3:23
Anonymous7-Sep-05 3:23 
QuestionPlease help me,,(MySql Front Installation) Pin
Jeeva Mary Varghese4-Sep-05 18:38
Jeeva Mary Varghese4-Sep-05 18:38 
QuestionUser And Password with ... Pin
mostafa_h4-Sep-05 8:58
mostafa_h4-Sep-05 8:58 
AnswerRe: User And Password with ... Pin
Colin Angus Mackay4-Sep-05 9:50
Colin Angus Mackay4-Sep-05 9:50 
QuestionUser And Password Pin
mostafa_h4-Sep-05 2:57
mostafa_h4-Sep-05 2:57 
AnswerRe: User And Password Pin
Colin Angus Mackay4-Sep-05 4:48
Colin Angus Mackay4-Sep-05 4:48 
Questionhow do i access a column from database Pin
ashima143-Sep-05 20:22
ashima143-Sep-05 20:22 
AnswerRe: how do i access a column from database Pin
Colin Angus Mackay3-Sep-05 21:31
Colin Angus Mackay3-Sep-05 21:31 
QuestionUpdate DataSet Pin
Zeeshan Gulzar3-Sep-05 4:15
Zeeshan Gulzar3-Sep-05 4:15 
AnswerRe: Update DataSet Pin
Besinci4-Sep-05 9:38
Besinci4-Sep-05 9:38 
GeneralRe: Update DataSet Pin
Zeeshan Gulzar6-Sep-05 5:51
Zeeshan Gulzar6-Sep-05 5:51 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.