Level Extreme platform
Subscription
Corporate profile
Products & Services
Support
Legal
Français
WestWind/database filter help
Message
From
27/06/2011 17:23:12
 
General information
Forum:
Visual FoxPro
Category:
Coding, syntax & commands
Miscellaneous
Thread ID:
01516279
Message ID:
01516368
Views:
52
>>>Look at SQLEXEC() function.
>>>
>>>Also, it's bad practice to embed parameters into your sql query. It opens you up to SQL injection attacks.
>>
>>http://xkcd.com/327/
>
>I have always loved this XKCD.
>
>Technically he's wrong. He should say parameterize but sanitize fits in the space better :)
>
>http://select-into.blogspot.com/2011/01/little-bobby-tables.html

Thanks for the link - that's the most concise explanation of strategies for migitation of SQL Injection I've ever seen.
Regards. Al

"Violence is the last refuge of the incompetent." -- Isaac Asimov
"Never let your sense of morals prevent you from doing what is right." -- Isaac Asimov

Neither a despot, nor a doormat, be

Every app wants to be a database app when it grows up
Previous
Next
Reply
Map
View

Click here to load this message in the networking platform