1095 EXPRESS: Removing SQL Injection Characters from File(s)
Removing SQL Injection Characters
Once all files are validated, you must remove all SQL Injection characters for security purposes. SQL Injections Characters are Ampersand, Apostrophe, Quotes, Double Dashes, pound sign, "less
than" and "greater than".
To find the characters, your .T95 file must be loaded inside the 1095 Express program. So you can see the people. Single click on any cell in the grid. Then press the F7 key, then type the # symbol,
for example.
- Click OK to search. If the symbol is found, the line will be at the top of the grid.
- Double click that line to see the form and the offending character. If you suspect many are present, close the Form and Press the F8 key to search for more,
or "count" how many are present.
If there are a large number of characters, they can be removed automatically by clicking on the Search Menu, then "Strip Character From File". It might be a good idea to save the file as Version
2, if you remove things, so you can get back to the original if necessary.