Boat Drinks  

Go Back   Boat Drinks > General > Computer and Consoles

Reply
 
Thread Tools Display Modes
Old 08-02-2009, 22:40   #11
kaiowas
The Stig
 
kaiowas's Avatar
 
Join Date: Jul 2006
Location: Fightertown USA
Posts: 1,458
Default

I know it's not the issue you've asked about but from quickly looking at your login code I suggest you go and read about SQL injection. Putting user inputted strings straight into a query without sanitizing them first is just asking for trouble.
__________________

Anal Fish Porn
kaiowas is offline   Reply With Quote
Old 08-02-2009, 22:53   #12
Mark
Screaming Orgasm
 
Join Date: Jul 2006
Location: Newbury
Posts: 15,194
Default

Ooh, good point - well spotted. Leaving SQL un-sanitized is asking for your entire database to be downloaded, tampered with, or just deleted, depending on the mood of the hacker at the time.
Mark is offline   Reply With Quote
Old 09-02-2009, 00:17   #13
jmc41
Absinthe
 
Join Date: Mar 2007
Posts: 1,070
Default

Might want to go down the $db->query route

All about OO then you can amend the connection string in a global class. Plus you can set it up to log execution time and stuff. My 2 cents anyway I've got a feeling I'm about to be flamed for some reason.
jmc41 is offline   Reply With Quote
Old 09-02-2009, 09:49   #14
Joe 90
Absinthe
 
Joe 90's Avatar
 
Join Date: Jan 2007
Location: Chester
Posts: 2,345
Default

ta.

I'd of liked to do it OO but i've never written OOPHP so just kept it procedural.
Too late now to change. deadline is today. :/
__________________
360 Blog | Join GiffGaff | Twitter
Joe 90 is offline   Reply With Quote
Old 09-02-2009, 14:55   #15
suarve
Nice weak cup of Earl Grey
 
Join Date: Jan 2009
Location: UK
Posts: 5
Default

Quote:
Originally Posted by |Show| View Post
ta.

I'd of liked to do it OO but i've never written OOPHP so just kept it procedural.
Too late now to change. deadline is today. :/
You should have made a simple php or include file with your connection string/details in, that you include at the top of every page.
suarve is offline   Reply With Quote
Old 09-02-2009, 16:07   #16
Joe 90
Absinthe
 
Joe 90's Avatar
 
Join Date: Jan 2007
Location: Chester
Posts: 2,345
Default

now that is one thing i did have, and always have.

two include files; dbparams and functions_main (connect & db_select)
__________________
360 Blog | Join GiffGaff | Twitter
Joe 90 is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 15:45.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.