Click here to Skip to main content
15,884,908 members
Home / Discussions / Database
   

Database

 
Questionconvert Pin
trilokharry16-Jun-08 21:40
trilokharry16-Jun-08 21:40 
AnswerRe: convert Pin
joemonvarghese80@yahoo.co.in16-Jun-08 22:27
joemonvarghese80@yahoo.co.in16-Jun-08 22:27 
AnswerRe: convert Pin
Krish - KP16-Jun-08 22:32
Krish - KP16-Jun-08 22:32 
AnswerRe: convert Pin
Ashfield16-Jun-08 22:44
Ashfield16-Jun-08 22:44 
AnswerRe: convert Pin
Mike Dimmick17-Jun-08 6:36
Mike Dimmick17-Jun-08 6:36 
AnswerRe: convert Pin
Niraj_Silver26-Jun-08 0:53
Niraj_Silver26-Jun-08 0:53 
QuestionSQL Injection - String replace best practice Pin
RCoate16-Jun-08 20:51
RCoate16-Jun-08 20:51 
AnswerRe: SQL Injection - String replace best practice Pin
Colin Angus Mackay16-Jun-08 21:43
Colin Angus Mackay16-Jun-08 21:43 
RCoate wrote:
I am already using stored procedures et al, but am now wondering what best practice would be for string replacement in parameters.

For SQL Server 2K5, I am already using:
Replace ' with ''


Why? If the string is arriving as a parameter there should be nothing to replace. Unless you aren't parameterising your query properly.

Does your SqlCommand.CommandText look like this:
EXEC MyStoredProcedure @Name='John O''Conner';



RCoate wrote:
But should I extend this to include:

Replace ; with [empty string]Replace drop[space] with [empty string]


If you replace ; with an empty string that means you can only submit one command at a time. You would also risk altering perfectly legitimate data if your replace was indiscriminate. Ditto with "Drop"

For example: Let's say a column was to contain some free form text. That text could include:
My favourite Dutch confectionary is known as "drop zoute"; It is the best.

If you are not careful you will alter perfectly legitimate data.

If you are, as you claim, already using stored procedures then you have little to worry about. The parameters and command are separated out by the .NET Framework (if you are using it properly - by adding the parameters to the Parameters collection on the SqlCommand.


GeneralRe: SQL Injection - String replace best practice Pin
RCoate17-Jun-08 15:59
RCoate17-Jun-08 15:59 
GeneralRe: SQL Injection - String replace best practice Pin
Colin Angus Mackay18-Jun-08 23:13
Colin Angus Mackay18-Jun-08 23:13 
QuestionMonth and Year Pin
trilokharry16-Jun-08 19:07
trilokharry16-Jun-08 19:07 
AnswerRe: Month and Year Pin
Alsvha16-Jun-08 19:54
Alsvha16-Jun-08 19:54 
GeneralRe: Month and Year Pin
trilokharry16-Jun-08 20:41
trilokharry16-Jun-08 20:41 
QuestionHow to search word starting with character 'a' Sql Full Text Indexing Pin
abhinish16-Jun-08 2:12
abhinish16-Jun-08 2:12 
AnswerRe: How to search word starting with character 'a' Sql Full Text Indexing Pin
SomeGuyThatIsMe16-Jun-08 7:44
SomeGuyThatIsMe16-Jun-08 7:44 
Questionsql query help Pin
csp16-Jun-08 0:42
csp16-Jun-08 0:42 
AnswerRe: sql query help Pin
A Wong16-Jun-08 2:46
A Wong16-Jun-08 2:46 
QuestionSP Transaction isolation level locking SQL 2005 [modified] Pin
pmpdesign15-Jun-08 21:56
pmpdesign15-Jun-08 21:56 
AnswerRe: SP Transaction isolation level locking SQL 2005 Pin
Alsvha16-Jun-08 2:21
Alsvha16-Jun-08 2:21 
GeneralRe: SP Transaction isolation level locking SQL 2005 Pin
Ashfield16-Jun-08 4:27
Ashfield16-Jun-08 4:27 
GeneralRe: SP Transaction isolation level locking SQL 2005 Pin
pmpdesign16-Jun-08 19:21
pmpdesign16-Jun-08 19:21 
GeneralRe: SP Transaction isolation level locking SQL 2005 Pin
Alsvha16-Jun-08 19:45
Alsvha16-Jun-08 19:45 
QuestionSOLVED Bumb SQL question - WHER AND syntax? [modified] Pin
Vaclav_14-Jun-08 13:50
Vaclav_14-Jun-08 13:50 
AnswerRe: Bumb SQL question - WHER AND syntax? Pin
Blue_Boy14-Jun-08 18:22
Blue_Boy14-Jun-08 18:22 
GeneralRe: Bumb SQL question - WHER AND syntax? Pin
Vaclav_14-Jun-08 18:43
Vaclav_14-Jun-08 18:43 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.