Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Michael Howard (and David LeBlanc) has a nice section in
"writing secure code" about encoding characters. In some
cases using char(0x27) as well as using entire words
encoded via 0xXXXXXXXXXX can be used. Watching for "'" is
not enough.
I think Michael is on this list.. any words Michael?

On Thu,...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus