Bag Of Chocolate Coated Rasins – Warning – May Contain SQL

addedsql.jpg

Source – The Daily WTF

About James McParlane

CTO Massive Interactive. Ex Computer Whiz Kid - Now Grumpy Old Guru.
This entry was posted in Coolhunting, Just Kidding. Bookmark the permalink.

1 Response to Bag Of Chocolate Coated Rasins – Warning – May Contain SQL

  1. emerson says:

    Hmmm… This exactly the kindof reason why i just spent a day finding a reliable way of sanitising printf style format strings in my sql library.

    First you parse the format string, identify all the arguments, then call your vsnprintf with chunks of the format string, making sure that the %s arguments are reprocessed to escape nasty things, and increment the va pointer between calls using types inferred from the format string.

    Works like a charm, may contain traces of nuts.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s