Register for your free account! | Forgot your password?

You last visited: Today at 12:12

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



Urgently. Correction login

Discussion on Urgently. Correction login within the Shaiya PServer Development forum part of the Shaiya Private Server category.

Reply
 
Old   #1
 
elite*gold: 100
Join Date: Jun 2012
Posts: 99
Received Thanks: 220
Exclamation Urgently. Correction login

And so, today I received this error

Code:
2014-11-16 19:59:50 err=-1, [Microsoft][ODBC SQL Server Driver]Function sequence error, SQL STATE: HY010, NATIVE ERROR: 0 (0x0)

2014-11-16 19:59:50 GetUser(): err=-1, query=EXEC usp_Try_GameLogin_Taiwan ''drop table users_master--  ','adfadf', 4242741533062725633,'80.83.239.38', [Microsoft][ODBC Driver Manager] Invalid cursor state, SQL STATE: 24000, NATIVE ERROR: 0 (0x0)

2014-11-16 19:59:51 err=-1, [Microsoft][ODBC SQL Server Driver][SQL Server]Invalid object name 'Users_Master'., SQL STATE: 42S02, NATIVE ERROR: 208 (0xD0)
Table user_data simply removed when entering the game. I think that this may be a bug on many servers. Who can help with this fix?
Призрак урана is offline  
Old 11/17/2014, 02:10   #2
 
nubness's Avatar
 
elite*gold: 10
Join Date: Jan 2012
Posts: 1,698
Received Thanks: 5,456
Code:
SET @UserID = REPLACE(@UserID, '''', '')
Homework:
Write me an essay on SQL injection.
Must contain full description of how exactly it was used to delete the table on your server.
nubness is offline  
Thanks
1 User
Old 11/17/2014, 10:21   #3
 
elite*gold: 100
Join Date: Jun 2012
Posts: 99
Received Thanks: 220
Quote:
Originally Posted by nubness View Post
Code:
SET @UserID = REPLACE(@UserID, '''', '')
Homework:
Write me an essay on SQL injection.
Must contain full description of how exactly it was used to delete the table on your server.
Very nice answer. I know it. But the problem is that the procedure is not even performed deletion occurs before performing.
Призрак урана is offline  
Old 11/17/2014, 12:38   #4
 
nubness's Avatar
 
elite*gold: 10
Join Date: Jan 2012
Posts: 1,698
Received Thanks: 5,456
Hmmm, you're right. I guess I can overlook things at 3 AM (that's my lame excuse for you).

There's a few solutions you might wanna try here:
Code:
DENY DELETE ON OBJECT::PS_UserData.dbo.Users_Master TO Shaiya (or whatever database admin name you have);
That's basically messing with permissions.

You can also create a new table with a foreign key referencing a column in the Users_Master. It will prevent the table from being dropped or truncated. For the delete instruction, you could do a trigger INSTEAD OF DELETE and have it do nothing.

These may not be the perfect solutions, but they can get it done.

Sorry for my previous post, I haven't checked it carefully.
nubness is offline  
Thanks
4 Users
Reply


Similar Threads Similar Threads
Help Quest Correction
04/29/2013 - Metin2 Private Server - 1 Replies
Hi! The devilscave.quest that .Nove posted, doesn't work for me, because when i login in the third level, i go back to city. So, i created my own devil's catacomb quest, without d.s/getf. In fact, the quest isn't a dungeon, but, when finally i kill Charon (vnum 2597), it teleports me to the azrael's level, but, it send me to town too! And... i don't know why.. if i change d.new_jump_all with pc.warp, it works! But... a lot of persons killing Charon to go to the last level, it's.. i mean,...
shop correction
07/12/2012 - Rappelz Private Server - 1 Replies
Hello, at me such problem, I bought a thing in Shop shop and not to the magician it to take away. How to correct? Give stored procedure, please
[Help]Need Correction If This Is Right.
06/01/2012 - Shaiya Private Server - 6 Replies
Anyone Wanna Tell Me If Its Correct For AP Per Min? :confused: USE GO /****** Object: StoredProcedure . Script Date: 05/31/2012 13:04:51 ******/ SET ANSI_NULLS ON GO SET QUOTED_IDENTIFIER ON GO /****** Object: Stored Procedure dbo.usp_Try_GameLogout_R Script Date: 2008-6-7 18:34:05 ******/
correction of the legion?
01/17/2008 - EO PServer Hosting - 0 Replies
somebody can postar the correction of the legion? please I beg debtor :)



All times are GMT +1. The time now is 12:13.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.