SQLi
SQLi (SQL
Injection)
·
Server-side attack
·
A query formatted: ‘ or ‘1’=’1’ -- is a SQL injection attack.
·
SELECT * FROM
·
Prevented
by
o Input
validation
o Removing
semi-colons, dashes, quotations, & commas
o Stored
procedures
No comments:
Post a Comment