On Thu, 03 Jun 2004 16:12:19 +1200, Dave - Dave.net.nz wrote:
> Nathan Mercer wrote:
>>>And they made the news. Mission accomplished?
>>>http://www.theinquirer.net/?article=16120
>
>> A SQL injection attack - pretty boring and not rocket science
>
> and not patched?
if were talking about the same thing sql injection "attacks" have more to
do with shoddy web design than anything else.
basically all database access should go through buisness & database logic -
validation. that way you can catch when somebody tries to "inject" their
sql into a database operation.
--
-------------------------------------------
Steven H, 3rd Year B.I.T. Otago Polytechnic
..net Geek