sqlite escape string
#6

Quote:
Originally Posted by rymax99
Посмотреть сообщение
Rare? If you run a server of any kind of decent size for any extended period of time, you'll find out very quickly that it's not all that rare. Or, you won't find out and you'll just wonder how Jim Jones with 1 playing hours keeps getting $900m.

Worst case here is your database being dumped and posted online. If you don't have some kind of(preferably automatic) backup mechanism in place when your server is of decent size, then you deserve what you get.
Sa-mp's input texts has way too many limits (chat > 128, name > 24 etc.) to effectively inject an SQL like what you said (getting whole database's data to post it online), also sa-mp's age average is ~15 I'm assuming (more of an observation, probably is wrong) and those don't have enough injection experience/can't make a code injecting and getting 128 chars of data at a time, hence SQL injection in sa-mp is "rare" but not impossible/non-existent
Reply


Messages In This Thread
sqlite escape string - by DavidBilla - 22.10.2015, 08:19
Re: sqlite escape string - by PrO.GameR - 22.10.2015, 08:27
Re: sqlite escape string - by DaniceMcHarley - 22.10.2015, 08:37
Re: sqlite escape string - by rymax99 - 22.10.2015, 09:37
Re: sqlite escape string - by Vince - 22.10.2015, 09:48
Re: sqlite escape string - by PrO.GameR - 22.10.2015, 10:48

Forum Jump:


Users browsing this thread: 1 Guest(s)