Click here to Skip to main content

The Weird and The Wonderful

   

The Weird and The Wonderful forum is a place to post Coding Horrors, Worst Practices, and the occasional flash of brilliance.

We all come across code that simply boggles the mind. Lazy kludges, embarrasing mistakes, horrid workarounds and developers just not quite getting it. And then somedays we come across - or write - the truly sublime.

Post your Best, your worst, and your most interesting. But please - no programming questions . This forum is purely for amusement and discussions on code snippets. All actual programming questions will be removed.

 
GeneralRe: What is null equal to? PinprofessionalRichard Deeming27-Aug-14 8:53 
GeneralRe: What is null equal to? Pinmemberjeron126-Aug-14 13:03 
GeneralRe: What is null equal to? Pinmembersloosecannon27-Aug-14 4:36 
GeneralRe: What is null equal to? PinmemberRob Grainger27-Aug-14 6:49 
GeneralRe: What is null equal to? PinmemberColborneGreg31-Aug-14 8:39 
GeneralRe: What is null equal to? Pinprofessionalsankarsan parida4-Sep-14 1:22 
GeneralRe: What is null equal to? PinmemberMunchies_Matt10-Sep-14 13:59 
GeneralGive a right username and a right password and you're in... Pinprofessionalyiangos25-Aug-14 5:38 
I was asked to make small amendments to an ages old ASP Classic website. So I tried to log into the "administration" area, didn't know what username/password to use, and opened up the code to see where in the database (MSAccess) I should look for valid credentials...
 
Behold (some details left out/altered to protect involved parties):
 
Dim msg
msg=""
Dim sql
sql="SELECT * FROM USERS WHERE (usr= '" + username +"')"
 
Dim rs
Set rs = Server.CreateObject("ADODB.Recordset")
rs.ActiveConnection = dbconnSTRING
rs.Source = sql
rs.CursorType = 0
rs.CursorLocation = 2
rs.Open()
 
if rs.Eof And rs.Bof then
	msg="Invalid username"
end if	
sql="SELECT * FROM USERS WHERE (pswd= '"+ password +"')"
rs.Close()
rs.Open(sql)
if rs.Eof And rs.Bof then
	if msg="Invalid username" then
		msg="Invalid username and password"
	else
		msg="Invalid password"
	end if	
end if
 
 

 
So basically if I know your username and I have my own account, I can use your username and my password and log in as you...
 
Nice eh?
Φευ! Εδόμεθα υπό ρηννοσχήμων λύκων!
(Alas! We're devoured by lamb-guised wolves!)

GeneralRe: Give a right username and a right password and you're in... Pinmembertgrt25-Aug-14 5:42 
GeneralRe: Give a right username and a right password and you're in... [modified] PinmemberPIEBALDconsult25-Aug-14 5:47 
GeneralRe: Give a right username and a right password and you're in... PinmemberBobJanova1-Sep-14 2:48 
GeneralRe: Give a right username and a right password and you're in... PinmemberJMK-NI25-Aug-14 5:53 
GeneralRe: Give a right username and a right password and you're in... PinprofessionalIan Shlasko25-Aug-14 5:55 
GeneralRe: Give a right username and a right password and you're in... Pinprofessionalyiangos25-Aug-14 6:41 
GeneralRe: Give a right username and a right password and you're in... Pinmemberdexterama25-Aug-14 6:06 
GeneralRe: Give a right username and a right password and you're in... Pinprofessionalyiangos25-Aug-14 6:50 
GeneralRe: Give a right username and a right password and you're in... PinmemberPIEBALDconsult25-Aug-14 6:56 
GeneralRe: Give a right username and a right password and you're in... Pinprofessionalyiangos25-Aug-14 7:05 
GeneralRe: Give a right username and a right password and you're in... PinprofessionalMarc Koutzarov29-Aug-14 22:44 
GeneralRe: Give a right username and a right password and you're in... Pinprofessionalyiangos31-Aug-14 7:38 
GeneralAndroid gravity constants PinprofessionalIndivara18-Aug-14 23:04 
GeneralRe: Android gravity constants PinprofessionalBernhard Hiller19-Aug-14 1:08 
GeneralRe: Android gravity constants PinprofessionalRichard Deeming19-Aug-14 2:47 
GeneralRe: Android gravity constants PinmemberKP Lee21-Aug-14 18:57 
GeneralRe: Android gravity constants PinprofessionalSander Rossel19-Aug-14 2:49 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.


Advertise | Privacy | Mobile
Web03 | 2.8.141220.1 | Last Updated 20 Dec 2014
Copyright © CodeProject, 1999-2014
All Rights Reserved. Terms of Service
Layout: fixed | fluid