Click here to Skip to main content
15,909,898 members
Home / Discussions / C#
   

C#

 
AnswerRe: String to Byte Array Conversion Pin
kristmun8-Jun-07 1:37
kristmun8-Jun-07 1:37 
AnswerRe: String to Byte Array Conversion Pin
Sathesh Sakthivel8-Jun-07 1:37
Sathesh Sakthivel8-Jun-07 1:37 
GeneralRe: String to Byte Array Conversion Thank you Pin
M. J. Jaya Chitra8-Jun-07 1:46
M. J. Jaya Chitra8-Jun-07 1:46 
GeneralRe: String to Byte Array Conversion Thank you Pin
Sathesh Sakthivel8-Jun-07 1:55
Sathesh Sakthivel8-Jun-07 1:55 
GeneralRe: String to Byte Array Conversion Pin
Guffa8-Jun-07 1:49
Guffa8-Jun-07 1:49 
GeneralRe: String to Byte Array Conversion Pin
Sathesh Sakthivel8-Jun-07 1:56
Sathesh Sakthivel8-Jun-07 1:56 
Questiongetting substring from a string Pin
Ankit Aneja8-Jun-07 1:18
Ankit Aneja8-Jun-07 1:18 
AnswerRe: getting substring from a string Pin
leppie8-Jun-07 1:20
leppie8-Jun-07 1:20 
AnswerRe: getting substring from a string Pin
Manas Bhardwaj8-Jun-07 1:32
professionalManas Bhardwaj8-Jun-07 1:32 
GeneralRe: getting substring from a string Pin
Ankit Aneja8-Jun-07 1:44
Ankit Aneja8-Jun-07 1:44 
GeneralRe: getting substring from a string Pin
Manas Bhardwaj8-Jun-07 1:48
professionalManas Bhardwaj8-Jun-07 1:48 
GeneralRe: getting substring from a string Pin
Ankit Aneja8-Jun-07 2:18
Ankit Aneja8-Jun-07 2:18 
GeneralRe: getting substring from a string Pin
Manas Bhardwaj8-Jun-07 2:21
professionalManas Bhardwaj8-Jun-07 2:21 
GeneralRe: getting substring from a string Pin
Ankit Aneja8-Jun-07 2:33
Ankit Aneja8-Jun-07 2:33 
GeneralRe: getting substring from a string Pin
Manas Bhardwaj8-Jun-07 2:39
professionalManas Bhardwaj8-Jun-07 2:39 
GeneralRe: getting substring from a string Pin
Ankit Aneja8-Jun-07 2:48
Ankit Aneja8-Jun-07 2:48 
GeneralRe: getting substring from a string Pin
Manas Bhardwaj8-Jun-07 3:00
professionalManas Bhardwaj8-Jun-07 3:00 
GeneralRe: getting substring from a string Pin
Ankit Aneja8-Jun-07 3:25
Ankit Aneja8-Jun-07 3:25 
GeneralRe: getting substring from a string Pin
Manas Bhardwaj8-Jun-07 3:28
professionalManas Bhardwaj8-Jun-07 3:28 
GeneralRe: getting substring from a string Pin
Ankit Aneja8-Jun-07 5:04
Ankit Aneja8-Jun-07 5:04 
QuestionInsert in Oracle Pin
Walaza8-Jun-07 0:26
Walaza8-Jun-07 0:26 
AnswerRe: Insert in Oracle Pin
Colin Angus Mackay8-Jun-07 0:36
Colin Angus Mackay8-Jun-07 0:36 
GeneralRe: Insert in Oracle Pin
Walaza8-Jun-07 0:46
Walaza8-Jun-07 0:46 
AnswerRe: Insert in Oracle Pin
Colin Angus Mackay8-Jun-07 0:53
Colin Angus Mackay8-Jun-07 0:53 
Walaza wrote:
string strSQL;
string insertValue= "'"+fname+"',"+"'"+lname+"',"+"'"+usrname+"',"+"'"+passwd+"',"+"'"+address+"',"+"'"+email+"',"+"'"+tester_id+"'";

strSQL = " INSERT INTO TESTER (FIRSTNAME, LASTNAME, USRNAME, PASSWD, ADDRESS, EMAIL, TESTERID) VALUES ("+insertValue+")";


This injects the values into the SQL. This is the source of a SQL Injection Attack, so you don't want to be injecting values.


Walaza wrote:
InsertCommand.Parameters.Add(":FIRSTNAME",System.Data.OracleClient.OracleType.VarChar,255);
InsertCommand.Parameters.Add(":LASTNAME",System.Data.OracleClient.OracleType.VarChar,255);
InsertCommand.Parameters.Add(":USRNAME",System.Data.OracleClient.OracleType.VarChar,255);
InsertCommand.Parameters.Add(":PASSWD",System.Data.OracleClient.OracleType.VarChar,255);
InsertCommand.Parameters.Add(":ADDRESS",System.Data.OracleClient.OracleType.VarChar,255);
InsertCommand.Parameters.Add(":EMAIL",System.Data.OracleClient.OracleType.VarChar,255);
InsertCommand.Parameters.Add(":TESTERID",System.Data.OracleClient.OracleType.VarChar,255);


What you want to do is alter the SQL String you've set up so that it doesn't inject values into the string.

So... Change insertValues to be a string that contains the parameter names rather than injecting the actual values. So it reads something like this:
string insertValue= ":FIRSTNAME, :LASTNAME, :USRNAME, :PASSWD, :ADDRESS, "+
                    ":EMAIL, :TESTERID";





Upcoming events:
* Glasgow: Mock Objects, SQL Server CLR Integration, Reporting Services, db4o, Dependency Injection with Spring ...
* Reading: Developer Day 5

Never write for other people. Write for yourself, because you have a passion for it. -- Marc Clifton


My website

QuestionPassing Objects to threads.. Pin
Eytukan8-Jun-07 0:20
Eytukan8-Jun-07 0:20 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.