4 ms·
The most important thing to stop sql injection is to validate your parameters on the server side.
by _trb_ 12y ago
The most important thing to stop sql injection is to validate your parameters on the server side.
- elchief 12y agoYes, but: 1. Not all SQL statements are parameterizable (dynamic identifiers vs literals) 2. Stopping SQL injection doesn't stop Insecure Direct Object References 3. Developers make mistakes 4. Plugins are a risk (example: http://www.zdnet.com/article/over-1-million-wordpress-websites-at-risk-from-sql-injection/ http://www.zdnet.com/article/over-1-million-wordpress-websit...) For parameterization to work you need to be perfect, always. My suggestions are for when someone else fucks up.