How are SQL Injection attacks prevented?

Image

SQL injection is a code injection technique, used to attack data driven applications like stSoftware.

stSoftware systems support a number of web accessible protocols including:-

  • ReST
  • SOAP
  • Web Forms
  • GWT RPC 

All protocols access the underlying data through the DAL ( data access layer). There is NO direct access to the underlying data store no matter which protocol is used. Each protocol accepts the request to read or write data and then perform the protocols validations and then passes the request on to the DAL to execute the request which in turn validates the request, checks the user's access and perform any validations before returning the result.

SQL & XSS attacks are automatically tested for each of the supported protocols. Listed below are the standard SQL injection strings attempted.

SQL Injection String
"&amp;%00<!--\'';你好
\'; DROP

How can stSoftware's CMS be used to manage events and resources?

Image

Events and Resources are managed through multiple Modules.

They are briefly outlined here;

Events

  • Details, site, time and date, duration


  • Invite attendees – select attendees then click send invitation button to send template email to all attendees & record status and attendance


Scheduler

  • scheduling events - resources according to availability, skill set, location


Admin

  • manage staff resources – availability rules, specialisations and rates


Timeline

  • Easy graphical interface for tasks, events, jobs (projects

What is the recommended upgrade schedule for self hosted systems?

Image

We recommend at least quarterly maintenance release are installed to your test environment, tested then promoted to your production system as part of the normal software maintenance cycle.

Regular and timely updates reduce the risks of running a live system that is out of sync with stSoftware's current version and enables your users to benefit from our R&D program, which is our investment and commitment to continually improve our systems for our customers (in recent years we have typically invested over

Site Wizard can create a professional site in minutes.

Image

Our site wizard is a simple way to get a professional website

Simply click on the wizard, enter your company details into the form provided and your information will automatically populate the pre-designed website template of your choice, giving you a quality website in minutes. You can choose to use this website, change the template, or tweak it to your hearts content, our system is accommodating and easy to use. 

There are a number of pre-designed site templates included in the base system.

What is the new Calendar?

Image

The new Calendar is a full-sized, drag & drop calendar. It uses AJAX to fetch events on-the-fly for each month/week/day.

Select from the filters to change the date range and items displayed according to type, category, status and assign to. Items are tasks, events, sales opportunities or jobs which have been entered and scheduled to a day and time. You'll see items in the calendar. Click on the item to see the details of the item. You can switch between the calendar and timeline view any time.

We've listed some handy Calendar Tips at the

What is the new Timeline module?

Image

Timeline is more than a graphical representation of your JobTrack data, it is interactive allowing you to link back to the item with a click to see the full details, edit and add details.

Select from the filters to change the date range and items displayed according to type, category and status. Items are tasks, events or sales opportunities which have been entered and scheduled to a day and time. You'll see items in timeline bands with a colour line representing their scheduled time and duration. The items you can view on

How do I send out event invitations?

Image

Create a new event.

Event

Invite your contacts by selecting the tab 'Invite Others'

Invite Others

 

Send the invitation via email 

Press the button "Send Invitation" to create an email populated with your contacts.

The email opens up with a pre defined template that can be changed.

email screen

 

Page Keywords Meta Tag

Image

The "keywords" meta tags is no longer used by any of the major search engines. Under some circumstances they can actually be scored negatively against the page rank, when a high count of irrelevant or duplicated key words are added. 

The system will automatically de-duplicate keywords if entered. For example if "SEO, meta, Seo,tags,,," is entered as the list of keywords, the list will be converted to "SEO, meta, tags"

Later releases will deprecate the entry of key words completely. Currently Google completely

Assigning a domain (host) name to your stSoftware hosted website or web system

Image

After you have registered a new domain name with a domain name (DNS) provider such goDaddy, or you have an exisiting domain name, you need to change the associated IP address so that your domain name points to stSoftware's servers.

Or contact us to add "Assigning your domain name" service to your website or websystem package and we'll manage it for you.

 

Assign your domain (host) name to the IP addresses of our servers

Have your DNS pointed to either of the two groupings of IP addresses below;

101

What is Web Forms?

Image

stSoftware's Forms is a web based designer

stSoftware's Forms is a web based designer that enables web forms to be created quickly and easily. Forms can then be consumed on most common mobile devices from the internet, anywhere and anytime. stSoftware's Forms are integrated with stSoftware's Workflow to automate business processes and deliver rich cloud applications.

Form Painter
 

Quick and Easy Forms Design

Empower business users and enhance developer productivity:

  • Auto-generate forms to support your business applications 
  • Customize forms quickly with