in reply to SQL Injection myths under DBI?

You didn't mention what DBD and DBMS you are using. The fact that you can't get some of those tricks to work with your combination of DBD/DBMS doesn't mean it's safe for others. Some simple tests and "thinking about" it are a good way to start, but they're not sufficient to "debunk" what you call myths.

Regardless of what you may think, placeholders are strongly recommended for security.

While DBI currently has no native support for multiple queries, that support may be coming and it's possible for DBDs to implement it whether or not DBI does.

  • Comment on Re: Discussion - SQL Injection under DBI