mp said:
Thanks for your opinion about my code. You are right about possibilities of
attack, but decent men should suggest that on different way. Your approach
is not professional, especially for person from consultants company.
Well, so far I have made it part of my life not to lie. I see a thief, I
call him a tihief. I see idiotic code, I call it idiotic code.
I'll avoid possibility of this attack later with parameterized queries and
user inputs validations.
Technically all you need to do is your homework with especial char handling.
If you are doing some little replaces on the iunput string, you are fine.
Anyway, I am not able to see connection between possibilities of SQL
Injection attack and my question???
This is totally your problem, because...
....in my answer I asked some questions about your code, and also made a
comment about your openness for SQL Injection.
You cared to ignore my answers and focus on the comment of the code.
So, what do you expect?
You did not provide enough information for sensible help, and have not
answered my questions yet. Without he answers I do not feel comfortable to
answer.
I am sorry but I never heard for you. I would like to believe, you a
brilliant mind and extraordinary programmer.
I am sure you have solution for this problem. Do you? May be not, may be you
are one ordinary man and average programmer. But do not worry, here is a lot
of folks to help you.
Spoken like someone who has no clue about SQL Injection attacks, and as
someone who - can not read. Like my answer and my questions to your problem.
I surely have a solution. IOnteresting point is, though, that your problem
technically SHOULD be a non-issue. This is why I asked questions.
That you tend to ignore them is basically one exact thing: your fault. Would
you have answered them, you would have been helped by now.
Please keep in sight and do not forget, this place is home of beginners and
extraordinary professionals who helps them.
Well, they should start learning to read before trying to program.
Means: when you come asking for help, and are asked to provide more
information, you should provide it if you expect a sensible answer.
--
Regards
Thomas Tomiczek
THONA Software & Consulting Ltd.
(Microsoft MVP C#/.NET)
(CTO PowerNodes Ltd.)