<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Programmers Quotes &#124; SysProg &#187; SQL</title>
	<atom:link href="http://www.sysprog.net/tag/sql/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sysprog.net</link>
	<description>Programmers' quotations about programming languages and IT</description>
	<lastBuildDate>Fri, 16 Apr 2010 02:46:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Use parameters in Dynamic SQL to prevent SQL Injection</title>
		<link>http://www.sysprog.net/2009/02/use-parameters-in-dynamic-sql-to-prevent-sql-injection/</link>
		<comments>http://www.sysprog.net/2009/02/use-parameters-in-dynamic-sql-to-prevent-sql-injection/#comments</comments>
		<pubDate>Mon, 02 Feb 2009 17:27:24 +0000</pubDate>
		<dc:creator>russell.smitheram</dc:creator>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[dynamic sql]]></category>
		<category><![CDATA[Parameters]]></category>
		<category><![CDATA[prevent sql injection]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[sql queries]]></category>

		<guid isPermaLink="false">http://www.sysprog.net/?p=268</guid>
		<description><![CDATA[When using Dynamic SQL to form your SQL queries, you got to be careful when concatenating user-generated input parameters. This is because malicious hackers can put in rogue characters that mean different things to the underlying database. Specifically you need to watch out for words like &#8220;DROP TABLE&#8221; &#8220;ALTER TABLE&#8221; etc that may occur in [...]]]></description>
		<wfw:commentRss>http://www.sysprog.net/2009/02/use-parameters-in-dynamic-sql-to-prevent-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced) (user agent is rejected)
Database Caching 11/24 queries in 0.024 seconds using disk
Content Delivery Network via Amazon Web Services: CloudFront: d1qys6rzdgknb6.cloudfront.net

Served from: www.sysprog.net @ 2010-09-09 17:11:18 -->