in reply to Simple question on SQL Injection
For detection, you could just count the occurences of the \' char somewhere... $dbh = DBI->connect(...); $sql = sprintf "SELECT name FROM users WHERE name=%s AND passwd=%s", $dbh->quote($bad_name), $dbh->quote($bad_pass); ...
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Simple question on SQL Injection
by andreas1234567 (Vicar) on Oct 09, 2007 at 18:14 UTC | |
|
Re^2: Simple question on SQL Injection
by captHij (Initiate) on Oct 10, 2007 at 13:23 UTC | |
|
Re^2: Simple question on SQL Injection
by radix (Initiate) on Oct 09, 2007 at 16:34 UTC | |
by runrig (Abbot) on Oct 09, 2007 at 17:10 UTC | |
by naikonta (Curate) on Oct 10, 2007 at 19:11 UTC |