Plateforme Level Extreme
Abonnement
Profil corporatif
Produits & Services
Support
Légal
English
Sqlexec from vfp fails
Message
De
25/05/2016 15:30:26
 
 
À
25/05/2016 11:52:41
Mike Yearwood
Toronto, Ontario, Canada
Information générale
Forum:
Microsoft SQL Server
Catégorie:
Syntaxe SQL
Divers
Thread ID:
01636625
Message ID:
01636801
Vues:
63
The attack vectors cited below, which are real even with parameterized SQL statements, are eliminated by a server side API creating the CRUD statements.
So for SOME scenarios, there is reason to avoid parameters, as their transport mechanism might be subverted and the whole statement might be altered.


>... There is zero reason to avoid using parameters.
>
>>>>Actually ***his*** source is safe against anything except for MIM attacks or total code rewite, which would succeed even in SQL parameter cases by rewriting the whole statement, unless there is further sanitizing server side.
Précédent
Suivant
Répondre
Fil
Voir

Click here to load this message in the networking platform