![]() |
RE: [Deleted]
ORIGINAL: MN/Kyle ORIGINAL: Germ ORIGINAL: KansasBBD What do you do, just Block the IP address? So when a legitment user post, it triggers a script that runs and creates all these bogus post. HNI is all user inputs(parameters). Adding a program in a search box that runs on a server. I do not want to show an example, I am sure Justin would skin me alive:D |
RE: Hey come the hacker antis' !!
Has this happened before on this forum. This is a bad thing.
|
RE: Hey come the hacker antis' !!
Germs a Computer nerd! ( i might pay for that one.... I gotta go check my bank account...[:o])
|
RE: [Deleted]
ORIGINAL: Germ I should show you some things people try to do on our sites. They will try anything to get in. It's user inputs that are easiest to use. HNI is all user inputs(parameters). Adding a program in a search box that runs on a server. I do not want to show an example, I am sure Justin would skin me alive:D |
RE: [Deleted]
ORIGINAL: MN/Kyle ORIGINAL: Germ I should show you some things people try to do on our sites. They will try anything to get in. It's user inputs that are easiest to use. HNI is all user inputs(parameters). Adding a program in a search box that runs on a server. I do not want to show an example, I am sure Justin would skin me alive:D |
RE: [Deleted]
Yep without a doubt it's XSS attack or SQL Injection.They have found a way in.
It could be SQL Injection also. HNI needs to run everything in Store Procedures and have parameters defined(size) to stop this. Ifsomeone is running SQL command in strings inside code, well it's very bad practice. These strings can have commands "Added" on. |
RE: [Deleted]
DO SOMETHING GERM!!
|
RE: [Deleted]
ORIGINAL: buckmaster DO SOMETHING GERM!! |
RE: [Deleted]
ORIGINAL: Germ Yep without a doubt it's XSS attack or SQL Injection.They have found a way in. It could be SQL Injection also. HNI needs to run everything in Store Procedures and have parameters defined(size) to stop this. Ifsomeone is running SQL command in strings inside code, well it's very bad practice. These strings can have commands "Added" on. ![]() ![]() ![]() |
RE: [Deleted]
I can't, LOL
If I was HNI first thing I would do is take all the SQL statements out of code and use Store Procedures with Paramters. You can set the size of your user input parameters and stop injections. Guys a moderator/admin cannot fix this, it has to be a developer. It's not HNI fault, it's bad coding practices. |
| All times are GMT -8. The time now is 01:25 PM. |
Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.