4 ms·
Isn't SQL injection caused by ingesting raw user input though? Seems to me you always have to be careful with user-supplied data.
by peller 10y ago
Isn't SQL injection caused by ingesting raw user input though?
Seems to me you always have to be careful with user-supplied data.
- meowface 10y ago"Ingesting raw user input is good if you only use it to interface with other systems that provide a way to separate data from instructions or at least escape strings."
- foolfoolz 10y agosql injection is commonly caused by combining your query with its related data parameters in unsafe ways. you are emitting raw user input you received to another program, the database, it's your responsibility to give this to the DB safely. you still have to be careful, and when you follow all the right best practices you can safely ingest raw user input. I've worked at a company that escaped user input before inserting into the DB. it's a horrible nightmare I don't think anyone should have to experience.
- halomru 10y agoI would have said that SQL injection is caused by emitting unescaped user input to your SQL server
- tlrobinson 10y agoIf I call eval(string) am I emitting unescaped user input to the eval function? I guess the definition of "injest" here is reading bytes off the wire?
- john_reel 10y agoIf string is unescaped user input, then yes, you are.