Jump to content
Xtreme .Net Talk

Recommended Posts

Posted (edited)

Good morning all,

 

We have a procedure that requires us to validate all input for text fields; if the input contains certain characters or key words, we must force the user to re-enter alternative data. Some of the characters that we look for at the start of sentances are:

' ;

/ >

-- <

admin @

declare =

 

Some of the characters that we look for at the end of sentances are:

one

>

 

The keywords that we look for are:

@@ xss

__ (double underscore) NULL

varchar ‘’ (double single quote)

ascii ';

cursor exec (followed by space)

-- char(

src

 

I have added the regular expression validator to my web page and have entered the following custom validator:

^'|^;|^/|^>|^--|^<|^admin|^@|^declare|^=|one$|>$|@@|xss|__|null|varchar|''|ascii|';|cursor|exec |--|char|src

 

The validator does not fire for any of my illegal characters, how can I set the above custom validator to "not equals"? I know that I can use the Regex.IsMatch function within the code, but thought that by using the regular expression control may be safer.

 

Mike55.

Edited by mike55

A Client refers to the person who incurs the development cost.

A Customer refers to the person that pays to use the product.

------

My software never has bugs. It just develops random features. (Mosabama vbforums.com)

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...