[FIX] Security match sql (#925)

* Added PrepForSQL function

performs a check to a string with expected patterns to be matched.

* Bug Fixes

After talking with Stan I realized that it wasn't testing strings so I set it up to ensure data is a string.

I also reworded the event log.
This commit is contained in:
R0adRa93
2023-01-18 12:53:38 -05:00
committed by GitHub
parent e6f5bf5ab6
commit 01e8597f07
+2 -1
View File
@@ -417,11 +417,12 @@ end
--- SQL Pattern Matching
function QBCore.Functions.PrepForSQL(source,data,pattern)
data = tostring(data)
local src = source
local player = QBCore.Functions.GetPlayer(src)
local result = string.match(data, pattern)
if not result or string.len(result) ~= string.len(data) then
TriggerEvent('qb-log:server:CreateLog', 'anticheat', 'SQL Injection Attempted', 'red', string.format('%s Attempted a SQL Exploit!', player.PlayerData.license))
TriggerEvent('qb-log:server:CreateLog', 'anticheat', 'SQL Exploit Attempted', 'red', string.format('%s attempted to exploit SQL!', player.PlayerData.license))
return false
end
return true