Re: [opennms-devel] Be on the lookout for code that allows SQL injection

2009-09-13 Thread Alexander Hoogerhuis
Tarus Balog wrote: > On Aug 18, 2009, at 7:25 PM, DJ Gregor wrote: > >> Lastly, we might want to make a parameterization-friendly version of >> Querier to make it easier to upgrade old SQL queries in an SQL >> injection-resistant manner. > > Great idea. While there should be little danger to a ne

Re: [opennms-devel] Be on the lookout for code that allows SQL injection

2009-08-20 Thread Tarus Balog
On Aug 18, 2009, at 7:25 PM, DJ Gregor wrote: > Lastly, we might want to make a parameterization-friendly version of > Querier to make it easier to upgrade old SQL queries in an SQL > injection-resistant manner. Great idea. While there should be little danger to a network posed by owning an Op