View Single Post
Old 12-11-2009, 05:33 PM  
Linguist
Confirmed User
 
Join Date: Apr 2004
Location: Toronto, ON
Posts: 1,706
Quote:
Originally Posted by halfpint View Post
trouble is its the users that are using ' and not " when they are typing things like mod's
Like woj said, those users can do more than just cause an error, a few cleverly placed 's from malicious users and you can kiss your data goodbye. I wrote this a few weeks ago:

http://www.embracer.com/2009/databas...sql-injections
__________________
315-310
Linguist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote