<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1531850453904970924.post7986839671851966279..comments</id><updated>2011-06-19T18:20:12.927-04:00</updated><category term='bloggers'/><category term='computer graphics'/><category term='Microsoft'/><category term='finances'/><category term='songs'/><category term='conceptual products'/><category term='crafting'/><category term='personal'/><category term='online tools'/><category term='video games'/><category term='movies'/><category term='top lists'/><category term='bridge'/><category term='books'/><category term='programming'/><category term='random'/><category term='sony aibo'/><category term='videos'/><category term='robots'/><category term='marriage'/><category term='relationships'/><category term='ultimate frisbee'/><category term='Apple'/><category term='Google'/><category term='carnegie mellon'/><category term='board games'/><category term='products'/><category term='saving money'/><category term='interview'/><category term='travel'/><category term='howtos'/><category term='iPhone'/><category term='iTunes'/><category term='downloadable software'/><category term='current events'/><category term='food'/><category term='sports'/><category term='design'/><category term='laptops'/><category term='code'/><category term='job advice'/><category term='girl geek'/><category term='blogging'/><category term='OS'/><category term='performing arts'/><title type='text'>Comments on RoboJenny: Boxy jQuery Plug-in</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.robojenny.com/feeds/7986839671851966279/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1531850453904970924/7986839671851966279/comments/default'/><link rel='alternate' type='text/html' href='http://www.robojenny.com/2008/10/boxy-jquery-plug-in.html'/><author><name>RoboJenny</name><uri>http://www.blogger.com/profile/04085723385146006020</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_ZSO3PFmiAYw/SqCJUMEP7bI/AAAAAAAABAI/yohZgFFAiCk/S220/jlingithub.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>7</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1531850453904970924.post-7166042543773586613</id><published>2011-06-19T18:20:12.927-04:00</published><updated>2011-06-19T18:20:12.927-04:00</updated><title type='text'>do NOT pass SQL statements to the backend end. YOu...</title><content type='html'>do NOT pass SQL statements to the backend end. YOu have to assume that all input coming from the user is malicious, until you validate and filter it thoroughly.&lt;br /&gt;&lt;br /&gt;what&amp;#39;s frustrating is your example STILL shows this, 2 years after you post it. So now anyone that doesn&amp;#39;t know better is going to read your post, and you&amp;#39;ve just &amp;quot;tutored&amp;quot; an aspiring web developer to do things insecurely. &lt;br /&gt;&lt;br /&gt;this is a *great* example of insecure code that hackers like lulzsec and anonymous use to own websites in 2 seconds. &lt;br /&gt;&lt;br /&gt;Someone with a comp sci degree from a great school like carnegie M should know better.&lt;br /&gt;&lt;br /&gt;Fix your code!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1531850453904970924/7986839671851966279/comments/default/7166042543773586613'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1531850453904970924/7986839671851966279/comments/default/7166042543773586613'/><link rel='alternate' type='text/html' href='http://www.robojenny.com/2008/10/boxy-jquery-plug-in.html?showComment=1308522012927#c7166042543773586613' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.robojenny.com/2008/10/boxy-jquery-plug-in.html' ref='tag:blogger.com,1999:blog-1531850453904970924.post-7986839671851966279' source='http://www.blogger.com/feeds/1531850453904970924/posts/default/7986839671851966279' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-296657327'/></entry><entry><id>tag:blogger.com,1999:blog-1531850453904970924.post-8796486585285023050</id><published>2010-06-28T16:28:55.747-04:00</published><updated>2010-06-28T16:28:55.747-04:00</updated><title type='text'>Hi Robo,

is there any way to develop http://www.s...</title><content type='html'>Hi Robo,&lt;br /&gt;&lt;br /&gt;is there any way to develop http://www.shirtsmyway.com/design_myshirt.php this type of website in php and jquery.&lt;br /&gt;&lt;br /&gt;please advice</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1531850453904970924/7986839671851966279/comments/default/8796486585285023050'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1531850453904970924/7986839671851966279/comments/default/8796486585285023050'/><link rel='alternate' type='text/html' href='http://www.robojenny.com/2008/10/boxy-jquery-plug-in.html?showComment=1277756935747#c8796486585285023050' title=''/><author><name>Narendra</name><uri>http://www.blogger.com/profile/16697985954873033043</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.robojenny.com/2008/10/boxy-jquery-plug-in.html' ref='tag:blogger.com,1999:blog-1531850453904970924.post-7986839671851966279' source='http://www.blogger.com/feeds/1531850453904970924/posts/default/7986839671851966279' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1620489930'/></entry><entry><id>tag:blogger.com,1999:blog-1531850453904970924.post-1053420702168362780</id><published>2010-02-17T08:06:15.645-05:00</published><updated>2010-02-17T08:06:15.645-05:00</updated><title type='text'>Nice Cleavage</title><content type='html'>Nice Cleavage</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1531850453904970924/7986839671851966279/comments/default/1053420702168362780'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1531850453904970924/7986839671851966279/comments/default/1053420702168362780'/><link rel='alternate' type='text/html' href='http://www.robojenny.com/2008/10/boxy-jquery-plug-in.html?showComment=1266411975645#c1053420702168362780' title=''/><author><name>Cris</name><uri>http://www.blogger.com/profile/10505714231096373930</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.robojenny.com/2008/10/boxy-jquery-plug-in.html' ref='tag:blogger.com,1999:blog-1531850453904970924.post-7986839671851966279' source='http://www.blogger.com/feeds/1531850453904970924/posts/default/7986839671851966279' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-78910732'/></entry><entry><id>tag:blogger.com,1999:blog-1531850453904970924.post-2152444620867585923</id><published>2009-08-20T12:55:09.240-04:00</published><updated>2009-08-20T12:55:09.240-04:00</updated><title type='text'>Wow... very interesting. U directly do the sql upd...</title><content type='html'>Wow... very interesting. U directly do the sql update directly from the box itself. Would not it be much more easier to use ajax http.open instead?&lt;br /&gt;&lt;br /&gt;Not that I&amp;#39;m trying to be an expert or anything but thank ya for the logic you did on how to automatically hide boxy.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1531850453904970924/7986839671851966279/comments/default/2152444620867585923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1531850453904970924/7986839671851966279/comments/default/2152444620867585923'/><link rel='alternate' type='text/html' href='http://www.robojenny.com/2008/10/boxy-jquery-plug-in.html?showComment=1250787309240#c2152444620867585923' title=''/><author><name>Andy D. Hajime</name><uri>http://www.blogger.com/profile/09075459135863348664</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.robojenny.com/2008/10/boxy-jquery-plug-in.html' ref='tag:blogger.com,1999:blog-1531850453904970924.post-7986839671851966279' source='http://www.blogger.com/feeds/1531850453904970924/posts/default/7986839671851966279' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-280811722'/></entry><entry><id>tag:blogger.com,1999:blog-1531850453904970924.post-7136682576663934611</id><published>2008-10-26T08:08:00.000-04:00</published><updated>2008-10-26T08:08:00.000-04:00</updated><title type='text'>Could you email me please? I fear my email to you ...</title><content type='html'>Could you email me please? I fear my email to you must have been sent to your bulk/spam folder.&lt;BR/&gt;&lt;BR/&gt;I do not like to give out too much information in the comments, but I do want to let you know it's in regards to your BlogHerAds.&lt;BR/&gt;&lt;BR/&gt;Laura at BlogHer dot com&lt;BR/&gt;&lt;BR/&gt;I look forward to hearing from you!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1531850453904970924/7986839671851966279/comments/default/7136682576663934611'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1531850453904970924/7986839671851966279/comments/default/7136682576663934611'/><link rel='alternate' type='text/html' href='http://www.robojenny.com/2008/10/boxy-jquery-plug-in.html?showComment=1225022880000#c7136682576663934611' title=''/><author><name>Laura</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.robojenny.com/2008/10/boxy-jquery-plug-in.html' ref='tag:blogger.com,1999:blog-1531850453904970924.post-7986839671851966279' source='http://www.blogger.com/feeds/1531850453904970924/posts/default/7986839671851966279' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1384014137'/></entry><entry><id>tag:blogger.com,1999:blog-1531850453904970924.post-983899126161043586</id><published>2008-10-17T14:37:00.000-04:00</published><updated>2008-10-17T14:37:00.000-04:00</updated><title type='text'>@Ivan&lt;br&gt;&lt;br&gt;You're very right. I tried to gloss o...</title><content type='html'>@Ivan&lt;BR/&gt;&lt;BR/&gt;You're very right. I tried to gloss over it in the post, but I do have that marked as something to fix. I wrote it that way at first since I found it easier to debug and test since I could easily swap it out to be various SQL queries to check on it. I fully plan on fixing that problem before I deliver the code. I wrote the post now as opposed to waiting for the polished version since I wanted to get my notes down immediately for the jQuery and Boxy portions, which are new to me.&lt;BR/&gt;&lt;BR/&gt;If anyone choose to use my notes for their own applications, I also would suggest only doing it this way to test and then make sure to change it to pass only the parameters and keep the sql in whatever your equivalent of submit_sql.php after you're sure all the commands are working.&lt;BR/&gt;&lt;BR/&gt;Thanks for your comment.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1531850453904970924/7986839671851966279/comments/default/983899126161043586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1531850453904970924/7986839671851966279/comments/default/983899126161043586'/><link rel='alternate' type='text/html' href='http://www.robojenny.com/2008/10/boxy-jquery-plug-in.html?showComment=1224268620000#c983899126161043586' title=''/><author><name>RoboJenny</name><uri>http://www.blogger.com/profile/04085723385146006020</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://1.bp.blogspot.com/_ZSO3PFmiAYw/SKMhnlixNTI/AAAAAAAAAq0/t7gAKTek00g/s1600-R/jennysmile.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.robojenny.com/2008/10/boxy-jquery-plug-in.html' ref='tag:blogger.com,1999:blog-1531850453904970924.post-7986839671851966279' source='http://www.blogger.com/feeds/1531850453904970924/posts/default/7986839671851966279' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1140861305'/></entry><entry><id>tag:blogger.com,1999:blog-1531850453904970924.post-8537152092744296526</id><published>2008-10-17T14:32:00.000-04:00</published><updated>2008-10-17T14:32:00.000-04:00</updated><title type='text'>That's a security hole isn't it?  You're letting t...</title><content type='html'>That's a security hole isn't it?  You're letting the client set the complete sql statement.  This allows a malicious user to execute a function on demand via Firebug for example.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1531850453904970924/7986839671851966279/comments/default/8537152092744296526'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1531850453904970924/7986839671851966279/comments/default/8537152092744296526'/><link rel='alternate' type='text/html' href='http://www.robojenny.com/2008/10/boxy-jquery-plug-in.html?showComment=1224268320000#c8537152092744296526' title=''/><author><name>Ivan</name><uri>http://www.blogger.com/profile/00530381404081691368</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.robojenny.com/2008/10/boxy-jquery-plug-in.html' ref='tag:blogger.com,1999:blog-1531850453904970924.post-7986839671851966279' source='http://www.blogger.com/feeds/1531850453904970924/posts/default/7986839671851966279' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-363688843'/></entry></feed>
