Posted by Peter Fox on 03/13/06 10:06
Following on from fiziwig's message. . .
>What is the usual procedure for validating members to prevent bots from
>"registering"? Membership number (auto-indexed) is kind of a status
>thing, so we don't want the primo low numbers to get chewed up by bots
>before the site even goes live for the rest of the membership. How can
>I keep them out?
Err... Validate _every_ input _always_.
Look up SQL injection
BTW Data field s are cheap : You're causing more work by trying to use
low-numbered membership IDs as a status flag.
--
PETER FOX Not the same since the pancake business flopped
peterfox@eminent.demon.co.uk.not.this.bit.no.html
2 Tees Close, Witham, Essex.
Gravity beer in Essex <http://www.eminent.demon.co.uk>
Navigation:
[Reply to this message]
|