Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Lazy sanitizing of data for SQL queries

From: Lawrence, Gabriel <glawrence(at)ucsd.edu>
Date: Fri Jan 24 2003 - 16:30:50 EST


This may be an obvious one.... but, unless the db itself knew to unpact it internally, you'd lose all the benefits of being in a database...

Sorting would be funky, queries with any kind of string handling in them wouldn't work....

Seems a little like cutting of your nose... -gabe

-----Original Message-----
From: Sverre H. Huseby [mailto:shh@thathost.com] Sent: Friday, January 24, 2003 12:31 PM
To: HarryM
Cc: webappsec@securityfocus.com
Subject: Re: Lazy sanitizing of data for SQL queries

[HarryM]

| Perhaps a good way of lazily sanitising data to be inserted into

Yes. What would you do for columns that were not textual?

Sverre.

-- 
shh@thathost.com		Computer Geek?  Try my Nerd Quiz
http://shh.thathost.com/	
http://nerdquiz.thathost.com/
Received on Fri Jan 24 17:06:15 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:48 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library