Home page
SPONSOR AD SPONSOR AD

Topic: My feelings are hurt, now

in Forum: Official C3 Vette Registry Support/Issues/Comments


My feelings are hurt, now

Posted: 10/5/05 6:48pm Message 1 of 13
Profile Pic
Lifetime MemberLifetime Member
Moderator
Send PM
Duncanville, TX - USA
Joined: 11/8/2003
Posts: 20214
Vette(s): #1-1974 L-48 4spd Cp Med Red Metallic/Black deluxe int w/AC/tilt/tele./p/w-p/b/ Am-Fm/map light National/Regional/Chapter NCRS "Top Flight" #2-1985 Bright Red/Carmine Cp.L-98/auto Member: NCRS, NCRS Texas, Corvette Legends of Texas
Could somebody preeeeze help me find my way into the "Live Chat" room? I have been a member of C3VR since '03, and I have NEVER been able to join in the fun. I've had this same trouble with 3 different 'puters, so I'm pretty sure it's not that. I usually can at least get to the 'sign in' page, but no further. To-nite, tho, I get a new kick in the a#*!
If someone can "talk" me thru it, I'd really 'preciate it. I just
know you're all in there talking bad about ME!

This is what I'm getting to-nite, when I click on the "Live Chat" icon:

There was an error! It has been reported to the system administrator. It you continue to get this message for more than 1 day, please send an email to support@VR.com

Error 424: Object required


Microsoft JET Database Engine error '80040e14'

Syntax error (missing operator) in query expression 'Username = 'Adams' Apple';'.

/netchatter/login.asp, line 16

Adams' Apple38630.7852893519


Joel Adams
C3VR Lifetime Member #56    

My Link


(click for Texas-sized view!)
             NCRS

"Money can't buy happiness -- but somehow it's more comforting to cry in a CORVETTE than in a Kia"

SPONSOR AD:: (Our Sponsors help support C3VR)

My feelings are hurt, now

Posted: 10/5/05 6:51pm Message 2 of 13
Lifetime MemberLifetime Member
Send PM
Joined: 7/24/2003
Posts: 2150
Vette(s): 1982 Collector Edition #3413

Sounds like your pop up is blocking or your fire wall is restricted.

 




My feelings are hurt, now

Posted: 10/5/05 7:06pm Message 3 of 13
Profile Pic
Lifetime MemberLifetime Member
C3VR Founder
Send PM
Eagleville, PA - USA
Joined: 11/1/2001
Posts: 18408
Vette(s): Used to own a 1979 Corvette now owned by JB79
Try now. I think I fixed it.


-Adam Wartell
NCM Lifetime Member #1222
Founder: C3 Vette Registry 
C4 Vette Registry, C6 Vette Registry

My first Vette, now owned by JB79:

My feelings are hurt, now

Posted: 10/5/05 8:01pm Message 4 of 13
Profile Pic
Lifetime MemberLifetime Member
Moderator
Send PM
Duncanville, TX - USA
Joined: 11/8/2003
Posts: 20214
Vette(s): #1-1974 L-48 4spd Cp Med Red Metallic/Black deluxe int w/AC/tilt/tele./p/w-p/b/ Am-Fm/map light National/Regional/Chapter NCRS "Top Flight" #2-1985 Bright Red/Carmine Cp.L-98/auto Member: NCRS, NCRS Texas, Corvette Legends of Texas
Thanx, guys!!!


Joel Adams
C3VR Lifetime Member #56    

My Link


(click for Texas-sized view!)
             NCRS

"Money can't buy happiness -- but somehow it's more comforting to cry in a CORVETTE than in a Kia"

My feelings are hurt, now

Posted: 10/5/05 8:02pm Message 5 of 13
Lifetime MemberLifetime Member
Send PM
Joined: 7/24/2003
Posts: 2150
Vette(s): 1982 Collector Edition #3413
Get some sleep now....    


My feelings are hurt, now

Posted: 10/6/05 6:54pm Message 6 of 13
Profile Pic
Lifetime MemberLifetime Member
Moderator
Send PM
Duncanville, TX - USA
Joined: 11/8/2003
Posts: 20214
Vette(s): #1-1974 L-48 4spd Cp Med Red Metallic/Black deluxe int w/AC/tilt/tele./p/w-p/b/ Am-Fm/map light National/Regional/Chapter NCRS "Top Flight" #2-1985 Bright Red/Carmine Cp.L-98/auto Member: NCRS, NCRS Texas, Corvette Legends of Texas
Just some info for others who might have had this same problem Adam & Mike(Iron82) helped to solve the mystery(or decided to finally let me play with the "Big Dogs" ).
It was the fact that my screen name, Adams' Apple has an apostrophy in it. Seems the software didn't recognize/accept this type of data. Only took 2years to to discover this 'glitch'!!
Just kiddin, guys!

Thanks for the help on this, Adam & Mike!!! I really enjoyed being able to join in a little last nite. (I think Mike wanted to drive me even closer to the brink, cause he would I/M me at the same time I was "chatting", causing a considerable amount of cornfusion on my part, which, in reality, ain't all that hard to do! )
btw.....who put the fat, nekkid chick on my desktop? Adams' Apple38632.7912384259


Joel Adams
C3VR Lifetime Member #56    

My Link


(click for Texas-sized view!)
             NCRS

"Money can't buy happiness -- but somehow it's more comforting to cry in a CORVETTE than in a Kia"

My feelings are hurt, now

Posted: 10/7/05 5:01am Message 7 of 13
Lifetime MemberLifetime Member
Moderator
Send PM
BINGHAMTON, NY - USA
Joined: 7/19/2003
Posts: 3808
Vette(s): ......
Fat,NEKKID CHICK ......?????


C3VR Lifetime Member #93

My feelings are hurt, now

Posted: 10/7/05 5:37pm Message 8 of 13
Lifetime MemberLifetime Member
Send PM
Canada
Joined: 8/6/2004
Posts: 533
Vette(s): Coupe 74 - 454 Drive it like you stole it!
The apostrophy is a string delimiter in the SQL language (Structured Query Language).  By having one in your name, it terminates the one that was started at the beginning of your name and therefor, not including "Apple" AND making the reminder of the SQL command un-compilable. bla bla bla
 
Anyway, I could talk about it all night, but the reason I'm posting, is that I wonder how it was fixed.  Just by adding a second apostrophy to Adam's user name ? or by setting an option somewhere ?
 
If only by adding a second one; you still have a security exposure. It is called "SQL injection".  One of the oldest (and easiest) way to hack a website.  Adam, you can do some google search to familiarize yourself with this kind of threat and then ask your hosting company (and/or the maker of this forum software) if they include some kind of protection for this).  Make sure you tell them that you allow screen name with single quote.
 
In Adam's Apple case, it was a single quote problem, but Iron82 gave some good pointer if it happens to anybody else.  The "chat" might be working on a different port than your http proxy and you could have to punch a whole in your firewall/router if you have a recent and secured one or if you run any application like "Norton" or "ZoneLabs".  It could also be related to a browser that blocks pop-up (mine does : AvantBrowser).
 
Glad you can now get in after that long.
 



My feelings are hurt, now

Posted: 10/7/05 6:58pm Message 9 of 13
Profile Pic
Lifetime MemberLifetime Member
Moderator
Send PM
Duncanville, TX - USA
Joined: 11/8/2003
Posts: 20214
Vette(s): #1-1974 L-48 4spd Cp Med Red Metallic/Black deluxe int w/AC/tilt/tele./p/w-p/b/ Am-Fm/map light National/Regional/Chapter NCRS "Top Flight" #2-1985 Bright Red/Carmine Cp.L-98/auto Member: NCRS, NCRS Texas, Corvette Legends of Texas
Huh? Adams' Apple38632.7922222222


Joel Adams
C3VR Lifetime Member #56    

My Link


(click for Texas-sized view!)
             NCRS

"Money can't buy happiness -- but somehow it's more comforting to cry in a CORVETTE than in a Kia"

My feelings are hurt, now

Posted: 10/7/05 8:21pm Message 10 of 13
Profile Pic
Lifetime MemberLifetime Member
C3VR Founder
Send PM
Eagleville, PA - USA
Joined: 11/1/2001
Posts: 18408
Vette(s): Used to own a 1979 Corvette now owned by JB79

Stephane,

You are right about it being an issue with SQL Server.

As a programmer, I know all too well about the ' in SQL Queries causing a failier.  And when I coded the majority of the pages for this site, I made sure to account for it.  However, I did not write the code for the Chat Room. Apparently that person didn't account for ' in a user name.

The unfortunate part for Adams' Apple, was that he wasn't getting an error message that he could tell me about, and my site didn't report any errors (again, probably because I didn't write that code).

So, for Stephane and other techies... here's the fix:

strSQL = "SELECT * FROM Users WHERE UserName = '" & replace(strUserName, "'", "''") & "'"

Which causes each single ' to turn into two ' right next to each other like this: ''

That tells the database to use the '' as a single ' in the user name and not as part of the database query command.

Everyone confused now?




-Adam Wartell
NCM Lifetime Member #1222
Founder: C3 Vette Registry 
C4 Vette Registry, C6 Vette Registry

My first Vette, now owned by JB79:

in Forum: Official C3 Vette Registry Support/Issues/Comments


SPONSOR AD: (Our Sponsors help support C3VR)