Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - This Forum Software Can Be Very Programmer Hostile
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

This Forum Software Can Be Very Programmer Hostile

 Post Reply Post Reply
Author
Coco Brown View Drop Down
Senior Member
Senior Member
Avatar

Joined: 26 April 2002
Location: United States
Status: Offline
Points: 245
Post Options Post Options   Thanks (0) Thanks(0)   Quote Coco Brown Quote  Post ReplyReply Direct Link To This Post Topic: This Forum Software Can Be Very Programmer Hostile
    Posted: 26 July 2010 at 4:19pm
It's great that such attention is taken to security.  However, I run a small forum that caters to C++ programmers who develop plugins for our company's application.  As a result, there are a lot of code fragments posted that trip these security filters. 

For example, searching on "MSG_UPDATE", a standard command in our proprietary scripting language, will trip an SQL Injection warning.  The CODE tag does not stop the forum from formatting something like:


arr


The above was an array with an index of "i", but you can see it went ahead and treated it like the BBcode for italicizing.

Just a heads up.
Back to Top
Coco Brown View Drop Down
Senior Member
Senior Member
Avatar

Joined: 26 April 2002
Location: United States
Status: Offline
Points: 245
Post Options Post Options   Thanks (0) Thanks(0)   Quote Coco Brown Quote  Post ReplyReply Direct Link To This Post Posted: 26 July 2010 at 4:59pm
And I tested the _SELECT bit on this forum and I got:


Server Error in Forum Application
WARNING: SQL Injection attack detected.
Please contact the Forum Administrator.

Support Error Code:- err_SQLServer_SqlInjectionTest()
File Name:- functions_common.asp
Forum Version:- 10 alpha build 20091210

Error details:-

Try it.  Do a search on "_select".  When you get the results click on "View Topic" on any result.  You will get the above error message.

 As I said, not very friendly to searching out code.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 27 July 2010 at 9:40am
Will look in to this and getting a fix.

The _select one you mention in your second post has been fixed for the latest 9.x version.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 27 July 2010 at 2:10pm
The issue appears to be with the underscore _ due to URL encoding.

You can fix this issue by editing the file forum_posts.asp and adding the line below at line 183:-

'Decode URL underscore to prevent keyword search issues   
strPageQueryString = Replace(strPageQueryString, "%5F", "_")

Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.