in reply to Simple question on SQL Injection
No need to test, just use placeholders.
Okay, technically, this only prevents it from being real problem, and it won't allow you pass to some alternate logic (eg, blacklist the incoming IP) when you see an injection attempt. The problem is that detecting abuse it like trying to detect spam e-mail -- there are some that are obvious, and some that might be acceptable, but you need to know the context.
For instance, it's much easier to locate bad values in a numeric field, or if there should have only been a limited set of choices to validate against. If it's freeform text (eg, passwords), or even worse -- binary data into a blob (eg, an image file), you might not be able to validate it simply on what characters are present, but have to look for patterns, and even then, you might have false positives.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Simple question on SQL Injection
by radix (Initiate) on Oct 09, 2007 at 16:32 UTC | |
by jhourcle (Prior) on Oct 09, 2007 at 16:56 UTC | |
by AK108 (Friar) on Oct 10, 2007 at 03:18 UTC | |
by naikonta (Curate) on Oct 10, 2007 at 19:03 UTC | |
by AK108 (Friar) on Oct 11, 2007 at 05:05 UTC |