Databases

Posts 16–27 of 27 · Page 2 of 2
Quote Originally Posted by DawgiiStylz View Post
Ok, I'm curious about the security risks that everyone was talking about. How would you go about this while being 'secured'.

Which I'm thinking.. people can check where the program is communicating with.. such as websites and ect.. or via the code where you can look at strings on databases information that no one should have..

I read here that sql and php isn't secured.. what is a better alternative?
PHP in post is much more secure than Visual Basic directly connecting to the database.
PHP should be just fine, you'd be running it like a website,
Application Sends Login Data (Pre-MD5 hashed, etc.) => PHP Gets data => PHP Relays data via Localhost (for the users remote host) to the Database => PHP relays the results back to the application (encrypted or not, up to you.)
Quote Originally Posted by rileyjstrickland View Post
PHP in post is much more secure than Visual Basic directly connecting to the database.
PHP should be just fine, you'd be running it like a website,
Application Sends Login Data (Pre-MD5 hashed, etc.) => PHP Gets data => PHP Relays data via Localhost (for the users remote host) to the Database => PHP relays the results back to the application (encrypted or not, up to you.)
Make sense .. no clue how I would do that tho. I'm completely new to databases.. i'm just now getting the sql language thangy.. I needa read more on that and I have no experience with PHP.
What riley was saying,
Is that the application isn't communicating with the Database at all, it communicates with a PHP web page that uses localhost to then connect to the Database.

So, In a way, MPGH runs like so. PHPbb runs in a similar way.
Quote Originally Posted by Raow View Post
What riley was saying,
Is that the application isn't communicating with the Database at all, it communicates with a PHP web page that uses localhost to then connect to the Database.

So, In a way, MPGH runs like so. PHPbb runs in a similar way.
I understand how it works.. just don't know how to do it.

i just encrpyted my strings and hopefully that'll be enough. I don't think I need any further help
Quote Originally Posted by DawgiiStylz View Post

I understand how it works.. just don't know how to do it.

i just encrpyted my strings and hopefully that'll be enough. I don't think I need any further help
You could use a simple echo on the php?
PHP is really easy to understand, just look a few things up!
Quote Originally Posted by DawgiiStylz View Post

I understand how it works.. just don't know how to do it.

i just encrpyted my strings and hopefully that'll be enough. I don't think I need any further help
Hahaha, my bad.
And any encryption is capable of being decrypted, i'd suggest PHP as well, I've tried to use it before.
How would I check if something in a row exists.. like..

Before I insert into the table.. how would I go about checking if that item exists already? @Raow @rileyjstrickland
Quote Originally Posted by DawgiiStylz View Post
How would I check if something in a row exists.. like..

Before I insert into the table.. how would I go about checking if that item exists already? @Raow @rileyjstrickland
No idea, i'm inexperienced with databases, i have little knowledge.
Sorry :/
here...anway this is how i do it...
try it anyway ^^

dim k as integer
Public Sub Search()
k = 0 ' <==my flag if theres found data
con.open
dim dt as new DataTable("TableName")
dim rs as new oledb.oledbDataAdapter("Select * from TableName where Columnname='"& searchname &"' ",con)
rs.fill(dt)
'if your using datagridview..me? i use datagridview all the time i..just hide it ^^..
datagridview1.datasource = dt
datagridview1.refresh()
label1.text = dt****ws.count '<====this will be the flag ,,it counts the row numbers in the table dt("TableName")..


rs.dispose()
con.close

if val(label1.text) >= 1 then <<====when this value goes more than 1 or 1 then what you search is there..if not then value of label1 = 0 ..no data found
Msgbox("Data Found!")
k = 1
else
Msgbox("No Data Found!")
End if


End Sub


Public Sub Add_Data

con.open
dim rs as new oledb.oledbCommand("Insert into Tablename(colname1,colname2,colname3) values ( '"& colnameval1 &"' , '"& colnameval2 &"', '"& colnameval3 &"')",con) ' command for adding data into table..anyway..should have not included this.

rs.executenonquery

con.close

End sub

private sub button1_click
if k = 1 then '<<===remember the flag k as integer? ,,,,yep here it is
msgbox("Data already exist")
Else
msgbox("Can call add data")
add_data
End if
end sub
Quote Originally Posted by Joy4hacks View Post
here...anway this is how i do it...
try it anyway ^^

dim k as integer
Public Sub Search()
k = 0 ' <==my flag if theres found data
con.open
dim dt as new DataTable("TableName")
dim rs as new oledb.oledbDataAdapter("Select * from TableName where Columnname='"& searchname &"' ",con)
rs.fill(dt)
'if your using datagridview..me? i use datagridview all the time i..just hide it ^^..
datagridview1.datasource = dt
datagridview1.refresh()
label1.text = dt****ws.count '<====this will be the flag ,,it counts the row numbers in the table dt("TableName")..


rs.dispose()
con.close

if val(label1.text) >= 1 then <<====when this value goes more than 1 or 1 then what you search is there..if not then value of label1 = 0 ..no data found
Msgbox("Data Found!")
k = 1
else
Msgbox("No Data Found!")
End if


End Sub


Public Sub Add_Data

con.open
dim rs as new oledb.oledbCommand("Insert into Tablename(colname1,colname2,colname3) values ( '"& colnameval1 &"' , '"& colnameval2 &"', '"& colnameval3 &"')",con) ' command for adding data into table..anyway..should have not included this.

rs.executenonquery

con.close

End sub

private sub button1_click
if k = 1 then '<<===remember the flag k as integer? ,,,,yep here it is
msgbox("Data already exist")
Else
msgbox("Can call add data")
add_data
End if
end sub
Thanks. I have an idea now on how to do it.
Quote Originally Posted by DawgiiStylz View Post

Thanks. I have an idea now on how to do it.
Personally, I'd execute a select * where the data is what the user inputted, after which I would check if more than 0 rows are returned. If there are 0 rows (nothing is found) then the item doesn't exists, and if there is more than 0 then the item does exist.
mmm I'm sure this syntax is correct..


ds = dataset
Posts 16–27 of 27 · Page 2 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?