Re: solution for preventing injection attacks

2005-11-17 Thread Jasper Bryant-Greene
[EMAIL PROTECTED] wrote: I have an idea for preventing sql injection attacks, however it would have to be implemented by the database vendor. Let me know if I am on the right track, this totally off base, or already implemented somewhere... Lets say you could have a format string such as in pr

solution for preventing injection attacks

2005-11-17 Thread douglass_davis
I have an idea for preventing sql injection attacks, however it would have to be implemented by the database vendor. Let me know if I am on the right track, this totally off base, or already implemented somewhere... Lets say you could have a format string such as in printf $format=" SELECT %s