Author | Post | ||
velo |
Is it still possible to inject SQL string (hex values or sth like that) with single or double quotes although they are filtered? I mean is that filtering good against that types of attacks... fe: If I enter ' got \' If I enter \' I got \\ |
||
04.12.2004 09:58:31 |
|
||
paipai |
Read this, maybe it's useful. http://www.securityfocus.com/infocus/1768 http://www.spidynamics.com/papers/SQLInjectionWhitePaper.pdf http://www.ebcvg.com/articles.php?id=210 |
||
Edited by paipai on 04.12.2004 10:24:51 | |||
04.12.2004 10:21:16 |
|