Someone is crashing my server!
#4

Quote:
Originally Posted by MP2
Посмотреть сообщение
Looks like SQL injection. Print out the entire query. Make sure you escape the input string (mysql_real_escape_string() IIRC).
Yus

pawn Код:
new safestring[129] //129 is max input right? o_O

mysql_real_escape_string(inputtext,safestring);
Then the query becomes:

pawn Код:
new query[124];
format(query,sizeof(query),"UPDATE `accounts` SET `Admin`='%d' WHERE `name`='%s'",safestring,Name[playerid]);
mysql_query(query);
That's how i do it anyway. Been able to avoid it so far. Add a mysql_real_escape_string on each UPDATE /INSERT query (dialogs, OnPlayerText() etc).
Reply


Messages In This Thread
Someone is crashing my server! - by TheBosss - 30.01.2014, 15:17
Re: Someone is crashing my server! - by TheBosss - 30.01.2014, 17:12
Re: Someone is crashing my server! - by MP2 - 31.01.2014, 00:23
Re: Someone is crashing my server! - by DobbysGamertag - 31.01.2014, 01:10
Re: Someone is crashing my server! - by MP2 - 31.01.2014, 01:56
Re: Someone is crashing my server! - by TheBosss - 31.01.2014, 04:49
Re: Someone is crashing my server! - by StreetGT - 31.01.2014, 04:52
Re: Someone is crashing my server! - by PowerPC603 - 31.01.2014, 07:08
Re: Someone is crashing my server! - by SwisherSweet - 31.01.2014, 07:12
Re: Someone is crashing my server! - by TheBosss - 31.01.2014, 09:44

Forum Jump:


Users browsing this thread: 4 Guest(s)