Click here to Skip to main content
16,014,677 members
Home / Discussions / Database
   

Database

 
QuestionEscape Sequences.... Pin
Polite Programmer27-May-07 1:13
Polite Programmer27-May-07 1:13 
AnswerRe: Escape Sequences.... Pin
phyomgmgwan27-May-07 2:54
phyomgmgwan27-May-07 2:54 
AnswerRe: Escape Sequences.... Pin
Giorgi Dalakishvili27-May-07 3:00
mentorGiorgi Dalakishvili27-May-07 3:00 
AnswerRe: Escape Sequences.... Pin
Colin Angus Mackay27-May-07 4:54
Colin Angus Mackay27-May-07 4:54 
AnswerRe: Escape Sequences.... Pin
Ron Savage27-May-07 8:17
Ron Savage27-May-07 8:17 
GeneralRe: Escape Sequences.... Pin
Colin Angus Mackay27-May-07 12:01
Colin Angus Mackay27-May-07 12:01 
GeneralRe: Escape Sequences.... Pin
Ron Savage27-May-07 14:18
Ron Savage27-May-07 14:18 
GeneralRe: Escape Sequences.... Pin
Colin Angus Mackay27-May-07 14:27
Colin Angus Mackay27-May-07 14:27 
Ron Savage wrote:
If the entire query as written is part of his internal code, there is no danger.


That's untrue.

There is the possibility of a Second Order Attack. This is where supposedly clensed data that is already sitting in the database can be used to form an attack. All the data used is internal to the system at the time the SQL is formed, but the threat is just as real.


Upcoming events:
* Glasgow: SQL Server 2005 - XML and XML Query Plans, Mock Objects, SQL Server Reporting Services...

Never write for other people. Write for yourself, because you have a passion for it. -- Marc Clifton


My website

GeneralRe: Escape Sequences.... Pin
Ron Savage27-May-07 14:43
Ron Savage27-May-07 14:43 
GeneralRe: Escape Sequences.... Pin
Colin Angus Mackay27-May-07 15:08
Colin Angus Mackay27-May-07 15:08 
QuestionBack Up store Pin
pramodprakash200526-May-07 21:08
pramodprakash200526-May-07 21:08 
AnswerRe: Back Up store Pin
Colin Angus Mackay27-May-07 0:54
Colin Angus Mackay27-May-07 0:54 
QuestionConnecting to Database Pin
mrkeivan26-May-07 7:31
mrkeivan26-May-07 7:31 
AnswerRe: Connecting to Database Pin
Colin Angus Mackay27-May-07 0:52
Colin Angus Mackay27-May-07 0:52 
GeneralRe: Connecting to Database Pin
mrkeivan27-May-07 9:53
mrkeivan27-May-07 9:53 
GeneralRe: Connecting to Database Pin
Colin Angus Mackay27-May-07 12:02
Colin Angus Mackay27-May-07 12:02 
GeneralRe: Connecting to Database Pin
Colin Angus Mackay27-May-07 12:05
Colin Angus Mackay27-May-07 12:05 
QuestionTree View And Floders Directories Pin
FriendlySoluations26-May-07 3:09
FriendlySoluations26-May-07 3:09 
Questionsql Pin
raj@code26-May-07 0:13
raj@code26-May-07 0:13 
AnswerRe: sql Pin
Colin Angus Mackay26-May-07 0:45
Colin Angus Mackay26-May-07 0:45 
GeneralRe: sql Pin
raj@code26-May-07 0:55
raj@code26-May-07 0:55 
AnswerRe: sql Pin
Ron Savage27-May-07 8:40
Ron Savage27-May-07 8:40 
Questiontotal number of months between two dates (urgent need hlp me)..... Pin
Member 387988125-May-07 23:53
Member 387988125-May-07 23:53 
AnswerRe: total number of months between two dates (urgent need hlp me)..... Pin
raj@code26-May-07 0:38
raj@code26-May-07 0:38 
GeneralRe: total number of months between two dates (urgent need hlp me)..... Pin
Member 387988126-May-07 0:46
Member 387988126-May-07 0:46 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.