Page 2 of 2 FirstFirst 12
Results 17 to 22 of 22

Thread: It's slatin' time....

  1. #17
    Network|Geek kidzer's Avatar
    Join Date
    Jul 2005
    Location
    Aberdeenshire
    Posts
    1,732
    Thanks
    91
    Thanked
    46 times in 41 posts
    • kidzer's system
      • Motherboard:
      • $motherboard
      • CPU:
      • Intel Q6600
      • Memory:
      • 4GB
      • Storage:
      • 1TiB Samsung
      • Graphics card(s):
      • BFG 8800GTS OC
      • PSU:
      • Antec Truepower
      • Case:
      • Antec P160
      • Operating System:
      • Windows 7
      • Monitor(s):
      • 20" Viewsonic
      • Internet:
      • ~3Mbps ADSL (TalkTalk Business)
    Looks and works fine with me, FF @ 1280x1024

    Looks awesome!
    "If you're not on the edge, you're taking up too much room!"
    - me, 2005

  2. #18
    Member
    Join Date
    Jan 2005
    Location
    Terry and June Land
    Posts
    167
    Thanks
    0
    Thanked
    0 times in 0 posts
    Hi there

    The site looks great, however there is one thing you have overlooked. You need to validate your input from request.form and request.querystring. Also is you are using IIS (which I guess you are) you should really set up your own HTTP 500 error page - this will stop errors giving the baddies any clues about your code.

    I'll be glad to answer any questions if you have any!

    Best of Luck

  3. #19
    Banned
    Join Date
    Jan 2005
    Location
    Who Cares!
    Posts
    4,092
    Thanks
    8
    Thanked
    61 times in 52 posts
    Very nice looking, unique. Like it a lot.

  4. #20
    IBM
    IBM is offline
    there but for the grace of God, go I IBM's Avatar
    Join Date
    Dec 2003
    Location
    West London
    Posts
    4,187
    Thanks
    149
    Thanked
    244 times in 145 posts
    • IBM's system
      • Motherboard:
      • Asus P5K Deluxe
      • CPU:
      • Intel E6600 Core2Duo 2.40GHz
      • Memory:
      • 2x2GB kit (1GBx2), Ballistix 240-pin DIMM, DDR2 PC2-6400
      • Storage:
      • 150G WD SATA 10k RAPTOR, 500GB WD SATA Enterprise
      • Graphics card(s):
      • Leadtek NVIDIA GeForce PX8800GTS 640MB
      • PSU:
      • CORSAIR HX 620W MODULAR PSU
      • Case:
      • Antec P182 Black Case
      • Monitor(s):
      • Dell 2407WPF A04
      • Internet:
      • domestic zoom
    Herbert ... thanks for the Error 500 tip, will do. All the form info is validated, but only at DB level, I think it's pretty tight against SQL injection, but I'll be going back through before final launch to make sure it's all secure...
    sig removed by Zak33

  5. #21
    Member
    Join Date
    Jan 2005
    Location
    Terry and June Land
    Posts
    167
    Thanks
    0
    Thanked
    0 times in 0 posts
    Only way to do it!

    I can still get it to fallover though! What I used to do is subclass the request.form and request.querystring objects like this:

    Class QueryStringReader

    Function ReadValue(strName)

    Dim strTemp

    strTemp = Request.Form(strName)
    strTemp = Replace(strTemp, "<whatever is dodgy>", "")
    .....
    .....
    ReadValue = strTemp

    End Function

    End Class

    Then call this instead of request.querystring etc.....sorry if I am teaching you to suck eggs!

    Best of Luck

  6. #22
    IBM
    IBM is offline
    there but for the grace of God, go I IBM's Avatar
    Join Date
    Dec 2003
    Location
    West London
    Posts
    4,187
    Thanks
    149
    Thanked
    244 times in 145 posts
    • IBM's system
      • Motherboard:
      • Asus P5K Deluxe
      • CPU:
      • Intel E6600 Core2Duo 2.40GHz
      • Memory:
      • 2x2GB kit (1GBx2), Ballistix 240-pin DIMM, DDR2 PC2-6400
      • Storage:
      • 150G WD SATA 10k RAPTOR, 500GB WD SATA Enterprise
      • Graphics card(s):
      • Leadtek NVIDIA GeForce PX8800GTS 640MB
      • PSU:
      • CORSAIR HX 620W MODULAR PSU
      • Case:
      • Antec P182 Black Case
      • Monitor(s):
      • Dell 2407WPF A04
      • Internet:
      • domestic zoom
    No, not at all....I see what you mean, I think that most of my concerns are to do with the integrity of the database, which has parsing to prevent pure injection issues. Keeping the code itself never really occured to me as worthwhile since unless someone wants to hack the site (which seems more effort than it's worth tbh) there's no real major security issue....

    But it's a valid point and one worth bearing in mind...there aren't that many form elements, so shouldn't take too long to fix...
    sig removed by Zak33

Page 2 of 2 FirstFirst 12

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Top 5 All Time Games?
    By Stewart in forum Gaming
    Replies: 199
    Last Post: 30-09-2012, 01:53 AM
  2. Karting at LUNCH TIME :)
    By TiG in forum Automotive
    Replies: 15
    Last Post: 23-04-2004, 11:37 AM
  3. losing time
    By 5cupa in forum PC Hardware and Components
    Replies: 2
    Last Post: 03-12-2003, 03:28 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •