in reply to is this mentality safe?
"As long as I taint and use placeholders with DBI, theres no way they'll ever be a SQL injection through this web app"
Tainting helps, but won't solve the problem, because it's always possible to untaint poorly (e.g., if you black list unacceptable patterns, instead of white listing the acceptable ones).
Do you think that placeholders, by themselves, entirelly solve the problem of SQL injections? That's the question.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: is this mentality safe?
by clinton (Priest) on May 18, 2007 at 11:04 UTC | |
by Anonymous Monk on May 19, 2007 at 02:44 UTC | |
|
Re^2: is this mentality safe?
by Errto (Vicar) on May 18, 2007 at 21:13 UTC |