Re: SQL injection - Mailing list pgsql-general

From Dan Sugalski
Subject Re: SQL injection
Date
Msg-id a06230902bf8c118160ca@[192.168.0.3]
Whole thread Raw
In response to SQL injection  (Yonatan Ben-Nes <da@canaan.co.il>)
List pgsql-general
At 7:54 PM +0200 10/31/05, Yonatan Ben-Nes wrote:
>Hi all,
>
>I'm currently trying to build a defence against SQL INJECTION, after
>reading some material on it I arrived to few possible solutions and
>I would like to know if anyone can comment anything about them or
>maybe add a solution of its own:

Just out of curiosity, is this something that constant SQL (or SQL
generated by code) with placeholder variables won't protect against?
--
                Dan

--------------------------------------it's like this-------------------
Dan Sugalski                          even samurai
dan@sidhe.org                         have teddy bears and even
                                       teddy bears get drunk

pgsql-general by date:

Previous
From: Ben
Date:
Subject: Re: SQL injection
Next
From: "A. Kretschmer"
Date:
Subject: Re: replace() and Regular Expressions