this post was submitted on 18 Aug 2024
854 points (98.9% liked)

Cybersecurity - Memes

2474 readers
165 users here now

Only the hottest memes in Cybersecurity

founded 2 years ago
MODERATORS
 

Last week, I tried to register for a service and was really surprised by a password limit of 16 characters. Why on earth yould you impose such strict limits? Never heard of correct horse battery staple?

you are viewing a single comment's thread
view the rest of the comments
[–] HowManyNimons@lemmy.world 23 points 8 months ago (2 children)

ADD FIELD PASSWORD VARCHAR(16)

[–] Sibbo@sopuli.xyz 10 points 8 months ago

SELECT * FROM users WHERE name = "$name" OR password = "$password"

[–] cron@feddit.org 6 points 8 months ago* (last edited 8 months ago) (2 children)
sqlquery = "INSERT INTO users (username, password) VALUES ('" + username + "', '" + password + "')"

What could go wrong?

[–] Gremour@lemmy.world 14 points 8 months ago* (last edited 8 months ago) (1 children)

Password=a");drop table users;--

Alas, it's longer than 16 characters. Protection works!

[–] _bcron@midwest.social 5 points 8 months ago

They often don't allow semicolons but it's never stopped me from checking