So using placeholders prevents this from happening? The data is still sent to the db although not through the use of placeholders, but through other variables, cannot the hacker still intercept the information? I think this is where T comes in. I am looking into this right now.
ues I am trying to locate good documentation on the issue... nothing like a good technical doc to sink my teeth into.
ThanksIn reply to Re: Re: Using-T and Untainting SQL
by sdyates
in thread Using-T and Untainting SQL
by sdyates
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |