in reply to Re: SQL Injection myths under DBI
in thread SQL Injection myths under DBI?

I upvoted him even if I don't entirely agree because I think this is a good debate to be had. I tried some of this stuff myself a few months ago, and was surprised that the typical sample SQL injection attacks you see advertised didn't work (on my database and dbd) because it didn't execute multiple statements. What may be different is that, even after noticing that I decided to keep using placeholders, for the same reasons others have cited in this thread.

In other words, I think it's good that the OP tried to figure out how things work, but I think one should be wary of extrapolating this too far and reach the conclusion that SQL injection is "impossible".

Replies are listed 'Best First'.
Re^3: SQL Injection myths under DBI
by tilly (Archbishop) on Apr 12, 2005 at 19:07 UTC
    While I agree that it is good to try these things for yourself, I objected to his very wrong conclusion.