Welcome to WebmasterWorld Guest from 54.144.126.195

Forum Moderators: open

Message Too Old, No Replies

Prevent injection MSSql server

     

ktsirig

8:56 am on Oct 16, 2007 (gmt 0)

5+ Year Member



Hello,
I wanted to ask if anyone knows of a way to prevent injection in an SQL SERVER 2005. I mean, is there any way to do all the blocking in the server and not have to escape each special character one-by-one?
For example, in PHP I used mysql_escape_string and automatically the string was OK to send to the database... Is there something similar in SQL Server?

Thank you

blend27

10:03 am on Oct 16, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



msdn2.microsoft.com/en-us/library/ms161953.aspx, i guess to start with

ebby

2:57 pm on Oct 16, 2007 (gmt 0)

5+ Year Member



one of your best defenses is using stored procedures.
 

Featured Threads

Hot Threads This Week

Hot Threads This Month