*or* need to overide this method

Jan 6, 2009 at 10:13 AM
Hello,

the rplacment of or with *or* is really making us a lot of trouble is there a way to override this?

please advise,

Best Regards,

Yuval
Coordinator
Jan 6, 2009 at 9:56 PM
Edited Jan 6, 2009 at 9:57 PM
This is by design. Please refer to  http://www.codeplex.com/IIS6SQLInjection/Thread/View.aspx?ThreadId=37280
I won't release a version without the "or" filter since it will bring a security risk, but if you want to do it yourself I can tell you which lines to change in the source code.
Thanks,
Rodney

Jan 14, 2009 at 10:27 AM
Edited Jan 14, 2009 at 10:28 AM
Thank you for the reply.

I will be happy to get the information needed for the change.
it is changing the or to *or* even when it is part of a word like "word" will become w*or*d which makes many problem to our system.

also one more question: is the filter block Unicode attacks?


thank you

Yuval
Coordinator
Jan 14, 2009 at 7:30 PM
It is not supposed to change word to w*or*d. Are you having this problem?