Re: [libdbi-users] libdbi and SQL Injection

2014-01-10 Thread Markus Hoenicka
Am 2014-01-10 14:17, schrieb Markus Hoenicka: if I understand you correctly, you attempt to insert a value containing the string %s Saints going down tonight! using the libdbi function dbi_conn_queryf(). Thing is, dbi_conn_queryf() is intended to make dbi_conn_query() behave

Re: [libdbi-users] libdbi and SQL Injection

2014-01-10 Thread Markus Hoenicka
At 2014-01-10 15:56, Rick Robinson was heard to say: I have tried the following, which I believe is on the right track but the program crashes as soon as it gets to dbi_conn_quote_string_copy. I try to use dbi_conn_quote_string_copy to keep the bad string locked down, and then use

Re: [libdbi-users] libdbi and SQL Injection

2014-01-10 Thread Rick Robinson
As you suggested, switch to dbi_conn_query and it took care of the issue. Appreciate the quick responses and suggestions. Ill be spending more time on the manual this week:) Thanks, Rj On Fri, Jan 10, 2014 at 10:23 AM, Markus Hoenicka markus.hoeni...@mhoenicka.de wrote: At 2014-01-10 15:56,