Re: SQL injection, php and queueing multiple statement

Поиск
Список
Период
Сортировка
От Ivan Sergio Borgonovo
Тема Re: SQL injection, php and queueing multiple statement
Дата
Msg-id 20080412201731.1e751826@webthatworks.it
обсуждение исходный текст
Ответ на Re: SQL injection, php and queueing multiple statement  (Tom Lane <tgl@sss.pgh.pa.us>)
Ответы Re: SQL injection, php and queueing multiple statement
Re: SQL injection, php and queueing multiple statement
Список pgsql-general
On Sat, 12 Apr 2008 12:39:38 -0400
Tom Lane <tgl@sss.pgh.pa.us> wrote:

> Ivan Sergio Borgonovo <mail@webthatworks.it> writes:
> > I may sound naive but having a way to protect the DB from this
> > kind of injections looks as a common problem, I'd thought there
> > was already a common solution.
>
> Use prepared statements.

Yeah... but how can I effectively enforce the policy that ALL input
will be passed through prepared statements?

If I can't, and I doubt there is a system that will let me enforce
that policy at a reasonable cost, why not providing a safety net that
will at least raise the bar for the attacker at a very cheap cost?

If programmers didn't make errors or errors where cheap to find there
wouldn't be any sql injection problem.

--
Ivan Sergio Borgonovo
http://www.webthatworks.it


В списке pgsql-general по дате отправления:

Предыдущее
От: "Pavan Deolasee"
Дата:
Сообщение: Re: Postgres on shared network drive
Следующее
От: "Dawid Kuroczko"
Дата:
Сообщение: Re: Postgres on shared network drive