Re: [PHP] Request to bash/jump/screw my code

2008-12-08 Thread ceo
> * Your output isn't cleaned up when coming from the database. You need > to put a few stripslashes() instances in there. Actually, if you think you have to use stripslashes, then, in fact, you've used addslashes and/or Magic Quotes TWICE, and your db has BAD DATA in it. Fix the data int

Re: [PHP] Request to bash/jump/screw my code

2008-12-08 Thread Ryan S
> Any advise is also most welcome. 'Advise' is a verb. 'Advice' is a noun. No charge. LOL! Thanks! Got caught by the grammar and typo police but no ticket! Must be my lucky day! Cheers! R -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.ne

Re: [PHP] Request to bash/jump/screw my code

2008-12-08 Thread Daniel Brown
On Mon, Dec 8, 2008 at 1:05 PM, Rick Pasotto <[EMAIL PROTECTED]> wrote: > > http://ezee.se/funnies/show_funny.php?id=p88&sec=1 has: > > Posted by: \' OR id != \' On: 2008-12-08 13:24:59 > \' OR id != \' That was me, testing for SQL injection. -- http://www.parasane.net/ [EMAIL PRO

Re: [PHP] Request to bash/jump/screw my code

2008-12-08 Thread Rick Pasotto
On Mon, Dec 08, 2008 at 09:01:56AM -0800, Ryan S wrote: > Hello everyone, > > Recently I worked on a rather decent sized project and it just went > live yesterday. > > We cannot really afford a security specialist so would appreciate it > if you could hit our site with whatever you want to (just

Re: [PHP] Request to bash/jump/screw my code

2008-12-08 Thread Rick Pasotto
On Mon, Dec 08, 2008 at 09:01:56AM -0800, Ryan S wrote: > > Any advise is also most welcome. 'Advise' is a verb. 'Advice' is a noun. No charge. -- "I didn't understand this at first, but YOUR CONVINCING USE OF CAPITAL LETTERS HAS MADE IT ALL CLEAR TO ME." -- J. Nairn Rick Pasotto[EMA

Re: [PHP] Request to bash/jump/screw my code

2008-12-08 Thread Daniel Brown
On Mon, Dec 8, 2008 at 12:01 PM, Ryan S <[EMAIL PROTECTED]> wrote: > > We cannot really afford a security specialist so would appreciate it if you > could hit our site with whatever you want to (just dont take us offline with > something like a DDOS please) and tell us if you find any problems.

[PHP] Request to bash/jump/screw my code

2008-12-08 Thread Ryan S
Hello everyone, Recently I worked on a rather decent sized project and it just went live yesterday. We cannot really afford a security specialist so would appreciate it if you could hit our site with whatever you want to (just dont take us offline with something like a DDOS please) and tell us