【发布时间】:2019-09-16 18:41:33
【问题描述】:
我知道我没有将我的密码存储在哈希中,但对于这个数据库来说,这并不重要。
代码引用了一个将密码存储为纯文本的 SQL 数据库
代码如下:
/*Checks to see if the username and password matcch the database
If it does, it lets you in, if not you displays an error message*/
string user = textBox1.Text.ToString();
string pass = textBox2.Text;
MySqlConnection conn = new MySqlConnection(ConnectionString);
MySqlDataAdapter sda = new MySqlDataAdapter("SELECT COUNT(*) from Employees WHERE UserName = '"+(user)+ "' and Password = '"+(pass)+"' collate Latin1_Genral_CS_AS", conn);
DataTable dt = new DataTable();
sda.Fill(dt);
if(dt.Rows[0][0].ToString() == "1")
{
HomeScreen home = new HomeScreen();
this.Hide();
home.ShowDialog();
}
else
{
MessageBox.Show("Incorrect Username or Password", "alter", MessageBoxButtons.OK, MessageBoxIcon.Error );
}
【问题讨论】:
-
那么你的问题是什么? BTW
Latin1_Genral_CS_AS(原文如此!请注意一般缺少 e)不是有效的排序规则