Topic: "SQL filtered input" (page 1 of 1)

1
Author Post
velo
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
Is it still possible to inject SQL string (hex values or sth like that) with single or double quotes although they are filtered? I mean is that filtering good against that types of attacks...
fe: If I enter ' got \'
If I enter \' I got \\
private message
paipai
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
Read this, maybe it's useful.
http://www.securityfocus.com/infocus/1768
http://www.spidynamics.com/papers/SQLInjectionWhitePaper.pdf
http://www.ebcvg.com/articles.php?id=210
Edited by paipai on 04.12.2004 10:24:51
private message EMail

Topic: "SQL filtered input" (page 1 of 1)

1