3 ms·
I'm going to assume that they have a server-side validation script running and the client side code is just to prevent/explain to mistaken users and if the serv
by ZeroComplete 16y ago
I'm going to assume that they have a server-side validation script running and the client side code is just to prevent/explain to mistaken users and if the server-side script every activates they know that someone's being malicious.
- donniefitz2 16y agoI was thinking the same thing. Let's hope that's true.
- ZeroComplete 16y agoIt would seem kind of stupid if they were smart enough to implement validation but not smart enough to limit user access to it. Of course there's no accounting for the depths of stupidity.
- chc 16y agoThat would actually not surprise me at all. There are a lot of Web devs who can make a site that renders in the browser and mostly works, but can't wrap their minds around the difference between server-side code and client-side. Browse through the JavaScript tag on Stack Overflow and you'll come across more than you can shake a stick at. Many people (either due to willful ignorance or a sad gap in their education) write functions like: function getTime() { <?php return time(); ?> } It's not at all improbable that somebody told them their site was vulnerable to SQL injection, so they took a brief glance at the Wikipedia page and said, "I know, I'll just stop people from writing this stuff." So they open up the page where people might be entering the malicious text and write some code that will stop them. They run it in their browser and it works — none of their SQL strings make it through. They have now fixed the problem, as far as they are concerned, and the site owner doesn't know enough to tell them how utterly braindead their approach is.
- robertduncan 16y agoThere may actually be a good reason for writing code like that. The time the content was generated by the server, perhaps?
- chc 16y agoThat wouldn't be a good reason for writing that code. Putting it in a function like that suggests that you expect the value to change. It's like the xkcd joke where a random() function is implemented to return 4, as determined by a fair dice roll. If you just wanted to store the time the page was generated, it would make more sense to use a constant — for example: window.pageBirthday = <?php echo time(); ?> Also, if they're on Stack Overflow asking why it doesn't correctly report the current time, that's a pretty good indicator that they're simply mistaken.
- yahelc 16y agoYeah, that function is useful for calculating the difference between server time and client time.
- spicyj 16y agoRight, I tried searching for "select" and it just redirected me back to the home page.
- nbpoole 16y agohttp://www.reddit.com/r/programming/comments/gdviz/how_not_to_guard_against_sql_injections_view/ http://www.reddit.com/r/programming/comments/gdviz/how_not_t... Based on some of the comments there, it doesn't look like it (or at least, it wasn't there several hours ago when Reddit stumbled upon the site). See http://www.reddit.com/r/programming/comments/gdviz/how_not_to_guard_against_sql_injections_view/c1muft1 http://www.reddit.com/r/programming/comments/gdviz/how_not_t... for some examples.
- julianc 16y agoMaybe the javascript is intentional, like a honeypot for hackers :)
- pbhjpbhj 16y agoYeah, maybe the 100+ validation errors in the markup are like a honeypot for web designers too ... I've not seen 1x1 gifs for a few years now. And leaking the MS SQL server errors and IIS errors are just adverts for MS (I only did genuine searches, "hotel" got me to an error page). I'm sure the silly long names are part of the ruse too. There is much that could be done with this site. Perhaps I could drop them a CV.
- somedev 16y agoSee my reply above. Yep, 1x1 gifs and table layouts were cutting edge back then ;)