•
•
•
•
What is DaniWeb IT Discussion Community?
You're currently browsing the MS SQL section within the Web Development category of DaniWeb, a massive community of 391,686 software developers, web developers, Internet marketers, and tech gurus who are all enthusiastic about making contacts, networking, and learning from each other. In fact, there are 3,204 IT professionals currently interacting right now! Registration is free, only takes a minute and lets you enjoy all of the interactive features of the site.
Please support our MS SQL advertiser:
Views: 744 | Replies: 2
![]() |
•
•
Join Date: Sep 2006
Location: San Diego, CA USA
Posts: 99
Reputation:
Rep Power: 2
Solved Threads: 2
•
•
Join Date: Mar 2008
Posts: 3
Reputation:
Rep Power: 0
Solved Threads: 1
The common method is to use regular expressions against the text that will be used in the where clause. The initial poster is correct in that stored procedures and parameters will stop this, but, if you are going to execute a sting built in the stored procedure you are still susceptible to an injection attack.
![]() |
•
•
•
•
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
•
•
•
•
•
•
•
•
DaniWeb MS SQL Marketplace
•
•
•
•
ad ad server ad serving advertising ajax architecture asp backup code injection crash daniweb database developer development dos doubleclick enterprise epilepsy google griefers hacker hackers internet javascript linux mail microsoft mmorpg msdn news novell office open pakistan qmail red hat rhel scsi security server smtp software source sql survey upgrade vista windows workspace youtube
- Previous Thread: CASE function
- Next Thread: Query Help - Is this Possible?


Linear Mode