Ask a Question related to ASP Database, Design and Development.

  1. #1

    Default SQL security


    Is it enough to simply use the replace function to convert single quotes
    into two single quotes while allowing users to insert data into a SQL
    statement?

    Like so-

    "SELECT whatever FROM table WHERE whatever = '" & replace(request("input"),
    "'", "''" )

    Thanks


    Qwip Guest

  2. Similar Questions and Discussions

    1. Change Flash Security Settings? Security ManagerOffline?
      Hello I have downloaded firefox and flash player, I have content which when I run it, flash blocks it wisely and reports that the page is trying...
    2. Error: code:Channel.Security.Error string:'Security
      Flex 2.0 beta 1 I created an mxml application with the following tag: <mx:WebService id="ws"...
    3. System.Security.SecurityException: Security error
      Dear All, The problem or error which I am getting while running my web application is as given below: Security Exception Description: The...
    4. Security tool to check CGI scripts for security holes/vulnerabities
      I'm searching for a good security tool that I can use regularly to scan all the programs/scripts in my web servers cgi-bin directory to identify...
    5. Asp.Net Security Analyser (new security tool by DDPlus)
      Hello I'm happy to announce that we (DDPlus) have just released the first stable version of our new Open Source Project: the Asp.Net Security...
  3. #2

    Default Re: SQL security

    On Sun, 12 Oct 2003 02:05:50 -0700, "Qwip" <asdas@emailasdasd.com>
    wrote:
    >
    >Is it enough to simply use the replace function to convert single quotes
    >into two single quotes while allowing users to insert data into a SQL
    >statement?
    >
    >Like so-
    >
    >"SELECT whatever FROM table WHERE whatever = '" & replace(request("input"),
    >"'", "''" )
    Umm... No. :)

    Take a look at the SQL Injection FAQ for starters:

    [url]http://www.sqlsecurity.com/[/url]

    Jeff
    Jeff Cochran Guest

Posting Permissions

  • You may not post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139