f the following link:
> http://www.net-security.org/dl/articles/IntegrigyIntrotoSQLInjectionAttacks.pdf
>
> Thx.
>
> Mike
>
>
> --- On Thu, 11/15/07, Antonio Petrelli <[EMAIL PROTECTED]> wrote:
>
> > From: Antonio Petrelli <[EMAIL PROTECTED]>
> > Subject: Re: Struts Val
), then you're not covered.
But if you use the placeholder and HQL or the Criteria APIs, then
you're covered.
Mike
--- On Thu, 11/15/07, Gary Affonso <[EMAIL PROTECTED]> wrote:
From: Gary Affonso <[EMAIL PROTECTED]>
Subject: Re: Struts Validator to Prevent SQL Injection Att
2007/11/15, Mike Duffy <[EMAIL PROTECTED]>:
> No matter where this is done, the basic problem is we have single quotes,
> double quotes, ampersands, semicolons, and parenthesis in our data.
This may be off topic, but does not is suffice to use prepared
statement and parameters to avoid such attac
2007/11/15, Mike Duffy <[EMAIL PROTECTED]>:
> Prepared statements if created correctly will work, but if your statements
> are created dynamically with text strings as the values instead of "?"
> placeholders problems can occur.
I wonder why do you create query strings this way: you can always
c
: Struts Validator to Prevent SQL Injection Attacks
> To: "Struts Users Mailing List"
> Cc: [EMAIL PROTECTED]
> Date: Thursday, November 15, 2007, 11:13 AM
> Dave Newton wrote:
> > --- Mike Duffy <[EMAIL PROTECTED]> wrote:
> >> Does anyone have a gre
mp;start=0&postdays=0&postorder=asc
And page 16 of the following link:
http://www.net-security.org/dl/articles/IntegrigyIntrotoSQLInjectionAttacks.pdf
Thx.
Mike
--- On Thu, 11/15/07, Antonio Petrelli <[EMAIL PROTECTED]> wrote:
> From: Antonio Petrelli <[EMAIL PROTECTED]>
.).
Has anyone created an elegant solution for this problem within the Struts
framework?
Mike
--- On Thu, 11/15/07, Dave Newton <[EMAIL PROTECTED]> wrote:
> From: Dave Newton <[EMAIL PROTECTED]>
> Subject: Re: Struts Validator to Prevent SQL Injection Attacks
> To: "
Dave Newton wrote:
--- Mike Duffy <[EMAIL PROTECTED]> wrote:
Does anyone have a great solution for a validator
that will prevent users from entering malicious SQL
into form entry text fields?
I'm not sure that belongs in a validator; unless you
never need to allow the use of a single quote. It
-
From: "Mike Duffy" <[EMAIL PROTECTED]>
To:
Sent: Thursday, November 15, 2007 12:42 PM
Subject: Struts Validator to Prevent SQL Injection Attacks
> Does anyone have a great solution for a validator that will prevent users
from entering malicious SQL into form entry text fields
Does anyone have a great solution for a validator that will prevent users from
entering malicious SQL into form entry text fields?
Thx.
Mike
Get easy, one-click access to your favorites.
Make Yahoo! yo
--- Mike Duffy <[EMAIL PROTECTED]> wrote:
> Does anyone have a great solution for a validator
> that will prevent users from entering malicious SQL
> into form entry text fields?
I'm not sure that belongs in a validator; unless you
never need to allow the use of a single quote. It is,
hoever unlik
11 matches
Mail list logo