Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - usernames
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

usernames

 Post Reply Post Reply
Author
fireau View Drop Down
Newbie
Newbie


Joined: 06 September 2003
Status: Offline
Points: 2
Post Options Post Options   Thanks (0) Thanks(0)   Quote fireau Quote  Post ReplyReply Direct Link To This Post Topic: usernames
    Posted: 10 April 2004 at 11:51am
This is an issue we have encountered.

It is posiible to make 2 usernames to be displayed the same way. Example I could register 2 usernames like this:

[fireau] as the first one
[fireau] as the second one.

And they would both display as [fireau]
Maybe the username should have the decodestring function applied to it before a check is made to whether it exists or not.


Back to Top
michael View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 April 2002
Location: United States
Status: Offline
Points: 4670
Post Options Post Options   Thanks (0) Thanks(0)   Quote michael Quote  Post ReplyReply Direct Link To This Post Posted: 10 April 2004 at 12:19pm
I don't really see the purpose of this but with code changes it would be possible to do so. If that is a thing you only want to do for one user you could also do it directly in the database, changing the code may be risky security wise...
Back to Top
fireau View Drop Down
Newbie
Newbie


Joined: 06 September 2003
Status: Offline
Points: 2
Post Options Post Options   Thanks (0) Thanks(0)   Quote fireau Quote  Post ReplyReply Direct Link To This Post Posted: 10 April 2004 at 12:31pm
There are several reasons to stop this, the least of them is confusion. We have had some users that did this, and tried to post as the original user.

I dont see the security issue in changing the code,.
Usernames get filtered prior to being checked if it exists in the database. All is required is to use decodestring(username) is the sql statement that checks if it exists in the db.


Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.