<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="https://syndication.webwiz.net/rss_namespace/">
 <channel>
  <title>Web Wiz Support and Community Forums : SQL code visible in page?</title>
  <link>https://forums.webwiz.net/</link>
  <description><![CDATA[This is an XML content feed of; Web Wiz Support and Community Forums : Web Wiz Forums : SQL code visible in page?]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Tue, 07 Apr 2026 14:55:33 +0000</pubDate>
  <lastBuildDate>Sun, 13 May 2007 21:31:55 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 12.08</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://forums.webwiz.net/RSS_post_feed.asp?TID=23313</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Web Wiz Support and Community Forums]]></title>
   <url>https://forums.webwiz.net/forum_images/web_wiz_forums.png</url>
   <link>https://forums.webwiz.net/</link>
  </image>
  <item>
   <title><![CDATA[SQL code visible in page? : The best thing to do is to findout...]]></title>
   <link>https://forums.webwiz.net/sql-code-visible-in-page_topic23313_post122765.html#122765</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 23313<br /><strong>Posted:</strong> 13&nbsp;May&nbsp;2007 at 9:31pm<br /><br />The best thing to do is to findout exactly the code the person is using then use the contact us section of this site to contact support with the details of how they are doing this, we will then beable to advise you how to prevent this from happening.]]>
   </description>
   <pubDate>Sun, 13 May 2007 21:31:55 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/sql-code-visible-in-page_topic23313_post122765.html#122765</guid>
  </item> 
  <item>
   <title><![CDATA[SQL code visible in page? : Thats correct, but we did minimal...]]></title>
   <link>https://forums.webwiz.net/sql-code-visible-in-page_topic23313_post122763.html#122763</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=25007">craigr</a><br /><strong>Subject:</strong> 23313<br /><strong>Posted:</strong> 13&nbsp;May&nbsp;2007 at 8:59pm<br /><br />Thats correct, but we did minimal code changes - as we didn't want to break the security.<DIV>&nbsp;</DIV><DIV>Can you give me some further pointers on the SQL hack please? eg how I can test it.&nbsp;PM if necessary please</DIV><DIV>&nbsp;</DIV><DIV>Cheers</DIV><DIV>Craig</DIV>]]>
   </description>
   <pubDate>Sun, 13 May 2007 20:59:23 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/sql-code-visible-in-page_topic23313_post122763.html#122763</guid>
  </item> 
  <item>
   <title><![CDATA[SQL code visible in page? : Your login page looks like it&amp;#039;s...]]></title>
   <link>https://forums.webwiz.net/sql-code-visible-in-page_topic23313_post122762.html#122762</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 23313<br /><strong>Posted:</strong> 13&nbsp;May&nbsp;2007 at 8:48pm<br /><br />Your login page looks like it's been modified to use the users email address instead of the username to login.<br><br>This would mean that the query your user is seeing to login is something which is not part of the original code and the user is probably using an SQL Injection to make the forum crash and display the SQL Query.<br><br>Web Wiz Forums does come with built in protection against SQL Injections, but if you have modified the code you may have accidentally removed the code that protects against SQL Injections from this query used to login users.<br>]]>
   </description>
   <pubDate>Sun, 13 May 2007 20:48:12 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/sql-code-visible-in-page_topic23313_post122762.html#122762</guid>
  </item> 
  <item>
   <title><![CDATA[SQL code visible in page? : Thanks Borg. Thats good to know....]]></title>
   <link>https://forums.webwiz.net/sql-code-visible-in-page_topic23313_post122761.html#122761</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=25007">craigr</a><br /><strong>Subject:</strong> 23313<br /><strong>Posted:</strong> 13&nbsp;May&nbsp;2007 at 8:19pm<br /><br />Thanks Borg. Thats good to know. <DIV>&nbsp;</DIV><DIV>However the (disgruntled) user has posted the first query in the login function in its entirety. eg select username...where handle = "" etc.</DIV><DIV>&nbsp;</DIV><DIV>I'm currently trying to get him to let me know how he is doing it and if it's the only one&nbsp;he sees. Once I have his feedback I'll post what he is doing.</DIV><DIV>&nbsp;</DIV><DIV>Cheers</DIV><DIV>Craig</DIV>]]>
   </description>
   <pubDate>Sun, 13 May 2007 20:19:03 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/sql-code-visible-in-page_topic23313_post122761.html#122761</guid>
  </item> 
  <item>
   <title><![CDATA[SQL code visible in page? : The connection code will not be...]]></title>
   <link>https://forums.webwiz.net/sql-code-visible-in-page_topic23313_post122758.html#122758</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 23313<br /><strong>Posted:</strong> 13&nbsp;May&nbsp;2007 at 7:02pm<br /><br />The connection code will not be displayed.<br><br>If there is a problem connecting to the SQL server, they may see an error like:-<br><br>Problem connecting to database xxx using username xxx<br><br>But this doesn't revel your password and is an error coursed by the server, not the software, the only way to prevent such error messages is to disable detailed ASP error messages in the web server itself, but this can course difficulties in debugging any issues you may have running ASP on your site.<br>]]>
   </description>
   <pubDate>Sun, 13 May 2007 19:02:05 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/sql-code-visible-in-page_topic23313_post122758.html#122758</guid>
  </item> 
  <item>
   <title><![CDATA[SQL code visible in page? : Hi  I have just been notified...]]></title>
   <link>https://forums.webwiz.net/sql-code-visible-in-page_topic23313_post122736.html#122736</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=25007">craigr</a><br /><strong>Subject:</strong> 23313<br /><strong>Posted:</strong> 13&nbsp;May&nbsp;2007 at 3:31am<br /><br />Hi<DIV>&nbsp;</DIV><DIV>I have just been notified by one of our more IT savvy users that the login SQL string is visible when they login. The address is <a href="http://www.fishing.net.nz/asp_forums/" target="_blank">www.fishing.net.nz/asp_forums/</A>. </DIV><DIV>&nbsp;</DIV><DIV>I've viewed the code and I cannot see it. Is there some debuging mode or way the SQL code can be captured &amp; displayed?</DIV><DIV>&nbsp;</DIV><DIV>Thanks is advance.</DIV><DIV>Craig</DIV>]]>
   </description>
   <pubDate>Sun, 13 May 2007 03:31:19 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/sql-code-visible-in-page_topic23313_post122736.html#122736</guid>
  </item> 
 </channel>
</rss>