Re: [GENERAL] SQL injection

2005-11-01 Thread Matthew D. Fuller
On Tue, Nov 01, 2005 at 08:57:04AM -0500 I heard the voice of Tom Lane, and lo! it spake thus: > > If you rely on applying an escaping function then it's pretty easy > to forget it in one or two places, and it only takes one hole to be > vulnerable :-(. The trick is to make it a religious ritual.

Re: [GENERAL] SQL injection

2005-11-01 Thread Matthew D. Fuller
On Mon, Oct 31, 2005 at 10:12:45AM -0800 I heard the voice of Ben, and lo! it spake thus: > Maybe I'm not very creative, but it sure seems to me that if you > escape your strings, make sure your numbers are numbers, and your > booleans are actually booleans, then you're protected Once nice tou

Re: [GENERAL] [OT] Tom's/Marc's spam filters?

2004-04-20 Thread Matthew D. Fuller
On Tue, Apr 20, 2004 at 05:35:51AM - I heard the voice of Jim Wilson, and lo! it spake thus: > Tom Lane said: > > > > 3. I have noticed that bouncing any machine that sends "HELO > > sss.pgh.pa.us" gets rid of a ton of spam and viruses. I don't know of > > any real clean way to do this, but I

Re: [GENERAL] Funniest way to write 'PostgreSQL'

2004-03-22 Thread Matthew D. Fuller
[ I'm a bit behind on email :] On Mon, Mar 15, 2004 at 07:41:52PM +0200 I heard the voice of Kaarel, and lo! it spake thus: > Kaarel wrote: > > >What is the funniest way you have seen 'PostgreSQL' written? > > > >Postgres and Postgre are a common way to say PostgreSQL...and they are > >not reall

Re: [GENERAL] Recomended FS

2003-10-20 Thread Matthew D. Fuller
On Mon, Oct 20, 2003 at 08:09:34AM -0400 I heard the voice of Jeff, and lo! it spake thus: > > insured shipping. But yeah, new scsi is quite expensive, but it can be > worth it... IMHO scsi is to be used in a raid, not alone. No one disk > can saturate the bw offered. (both ide and scsi). T