<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Some SQL injection attack misperceptions - and reality</title><link>http://blogs.msdn.com/b/glengordon/archive/2008/04/15/some-sql-injection-attack-misperceptions-and-reality.aspx</link><description>My colleague Brian just posted about an error page he encountered on a public ecommerce site, and the clues it gave him about how the coding of that site was wrong in a lot of ways.&amp;#160; He gave some good tips on fighting SQL Injection attacks, but I</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Some SQL injection attack misperceptions - and reality</title><link>http://blogs.msdn.com/b/glengordon/archive/2008/04/15/some-sql-injection-attack-misperceptions-and-reality.aspx#8407936</link><pubDate>Fri, 18 Apr 2008 18:03:17 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8407936</guid><dc:creator>Andy White</dc:creator><description>&lt;p&gt;&amp;gt;I'll just write code that replaces all the single quotes in the user's input with two single quotes in a row, and I'll be fine&lt;/p&gt;
&lt;p&gt;Just to be clear, I always use input validation with parameterized queries and stored procs and always try to avoid EXEC statements. &lt;/p&gt;
&lt;p&gt;But I have always been curious, how can the scheme of replacing all single quotes with two single quotes be defeated? Do you have an example?&lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8407936" width="1" height="1"&gt;</description></item><item><title>Microsoft news and tips &amp;raquo; Some SQL injection attack misperceptions - and reality</title><link>http://blogs.msdn.com/b/glengordon/archive/2008/04/15/some-sql-injection-attack-misperceptions-and-reality.aspx#8398195</link><pubDate>Tue, 15 Apr 2008 23:47:04 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8398195</guid><dc:creator>Microsoft news and tips &amp;raquo; Some SQL injection attack misperceptions - and reality</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://microsoftnews.askpcdoc.com/?p=2650"&gt;http://microsoftnews.askpcdoc.com/?p=2650&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8398195" width="1" height="1"&gt;</description></item></channel></rss>