Click here to Skip to main content
15,921,837 members
Home / Discussions / ASP.NET
   

ASP.NET

 
Questiondatabase manipulation with ASP.NET Pin
sgeezee20-Jun-06 9:48
sgeezee20-Jun-06 9:48 
AnswerRe: database manipulation with ASP.NET Pin
Raj Lal20-Jun-06 11:14
professionalRaj Lal20-Jun-06 11:14 
QuestionDatagrid-Boundcolumn.dataformatstring property Pin
Dhruvil20-Jun-06 9:33
Dhruvil20-Jun-06 9:33 
AnswerRe: Datagrid-Boundcolumn.dataformatstring property Pin
Nagraj Naik20-Jun-06 20:32
Nagraj Naik20-Jun-06 20:32 
QuestionEditing Somone Elses Work..... Pin
Matthew Hazlett20-Jun-06 8:47
Matthew Hazlett20-Jun-06 8:47 
AnswerRe: Editing Somone Elses Work..... Pin
Raj Lal20-Jun-06 11:16
professionalRaj Lal20-Jun-06 11:16 
QuestionMaximum open connections in ASP .NET? Pin
mcintyre23120-Jun-06 6:41
mcintyre23120-Jun-06 6:41 
QuestionAre sql query command strings secure in ASP.NET? Pin
timothymburke20-Jun-06 5:43
timothymburke20-Jun-06 5:43 
I have a question about ASP.NET security. We learned in the advanced ASP.NET class not to put our username and password in our code behind page because a hacker could get to it there. They said as a good security practice we should put it in the web.config file, encrypt it, memorize the password, and lock the server room door, but what about our sql commands or query strings?

If in our code behind page we have the query:
SELECT * FROM SQLUSERDATA WHERE USER = txtUSER.Text AND PASS = txtPASS.Text

What stops a hacker from getting to the string in memory and changing it to:
SELECT * FROM SQLUSERDATA

to return all the usernames, passwords, addresses, etc. from our database. I'm assuming if they can get to the sql connection string to steal the password when it is in the code behind then they can just as easily get to sql query command string.

I am trying to put the command string for my sql query into web.config then pull in the username and password from the webform but cannot use varibles in the string because web.config does not see my webform objects. I googled for hours but could only find help with the connection string which everyone knows how to do by now, and doesn't need varibles from the webform. How do I make the following code work in the web.config:
SELECT * FROM SQLUSERDATA WHERE USER = txtUSER.Text AND PASS = txtPASS.Text

or what would be the most secure way to hide my query string from hackers?

Thanks!

timothymburke@hotmail.com
AnswerRe: Are sql query command strings secure in ASP.NET? Pin
Guffa20-Jun-06 6:38
Guffa20-Jun-06 6:38 
GeneralRe: Are sql query command strings secure in ASP.NET? [modified] Pin
timothymburke20-Jun-06 7:46
timothymburke20-Jun-06 7:46 
AnswerRe: Are sql query command strings secure in ASP.NET? Pin
Guffa20-Jun-06 11:51
Guffa20-Jun-06 11:51 
AnswerRe: Are sql query command strings secure in ASP.NET? Pin
ToddHileHoffer20-Jun-06 7:37
ToddHileHoffer20-Jun-06 7:37 
AnswerRe: Are sql query command strings secure in ASP.NET? Pin
mtone20-Jun-06 7:42
mtone20-Jun-06 7:42 
AnswerRe: Are sql query command strings secure in ASP.NET? Pin
Vasudevan Deepak Kumar20-Jun-06 23:06
Vasudevan Deepak Kumar20-Jun-06 23:06 
QuestionHow to fill data into a table dynamically? Pin
pitturamakrishna20-Jun-06 5:23
pitturamakrishna20-Jun-06 5:23 
AnswerRe: How to fill data into a table dynamically? Pin
ToddHileHoffer20-Jun-06 5:35
ToddHileHoffer20-Jun-06 5:35 
Questionhi, please i wanna know how ViewState works Pin
Mohammed Amine20-Jun-06 4:55
Mohammed Amine20-Jun-06 4:55 
AnswerRe: hi, please i wanna know how ViewState works Pin
J4amieC20-Jun-06 5:03
J4amieC20-Jun-06 5:03 
Questioncreate button dynamically Pin
surshbabuk20-Jun-06 4:26
surshbabuk20-Jun-06 4:26 
AnswerRe: create button dynamically Pin
Keith Barrow20-Jun-06 5:08
professionalKeith Barrow20-Jun-06 5:08 
Questionhow to control header ,sidemenu and footer for everypage? Pin
campbells20-Jun-06 4:07
campbells20-Jun-06 4:07 
AnswerRe: how to control header ,sidemenu and footer for everypage? Pin
minhpc_bk20-Jun-06 15:22
minhpc_bk20-Jun-06 15:22 
QuestionFile breakdown not working Pin
Brendan Vogt20-Jun-06 4:05
Brendan Vogt20-Jun-06 4:05 
AnswerRe: File breakdown not working Pin
Paddy Boyd20-Jun-06 4:31
Paddy Boyd20-Jun-06 4:31 
Question2 Version running on same Web server Pin
mtone20-Jun-06 3:13
mtone20-Jun-06 3:13 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.