in reply to Re^2: SQL Injection myths under DBI
in thread SQL Injection myths under DBI?

Regarding null-byte, please explain how can I receive this through CGI.

Easy:

scipt.cgi?name=admin'%00

Regarding the judgement you´ve made, "abysmally stupid advice", please, my friend, this is not the place to be this rude. This is not behaviour for a monk!

Well, I think it is stupid advice :-) I'm not trying to be rude, and I'm not saying that you are stupid. You're quite right in questioning something that you see as cargo-cult programming. It's just that you are advocating ignoring something that is potentially dangerous without knowing the full scale of the problem.