in reply to Re: Using-T and Untainting SQL
in thread Using-T and Untainting SQL
So using placeholders prevents this from happening? The data is still sent to the db although not through the use of placeholders, but through other variables, cannot the hacker still intercept the information? I think this is where T comes in. I am looking into this right now.
ues I am trying to locate good documentation on the issue... nothing like a good technical doc to sink my teeth into.
Thanks
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re3: Using-T and Untainting SQL
by PotPieMan (Hermit) on Apr 29, 2002 at 18:55 UTC | |
by sdyates (Scribe) on Apr 30, 2002 at 20:02 UTC | |
by PotPieMan (Hermit) on Apr 30, 2002 at 23:48 UTC |