3 ms·
For every person that gets SQL strong concatenation right 20 get it wrong. And there are simple and safe ways to write arbitrary SQL queries without using conca
by bitexploder 6y ago
For every person that gets SQL strong concatenation right 20 get it wrong. And there are simple and safe ways to write arbitrary SQL queries without using concatenation. Parmeterized queries are available everywhere. There is a reason we tell everyone not to do it and that reason is that it’s dangerous and almost everyone screws it up. I have found your case to be the exception in 13 years as an infosec researcher and consultant.