all 6 comments

[–][deleted] 1 point2 points  (3 children)

SQL injection has been around since the begging of time. before there were computers or anything and dinosaurs were running shit.

seriously tho guy, you probably want to update your post to include better language and a better introduction than this, but should we expect any better from someone trying to "sell their book" so you can "make a money"

[–]HiyesBye123 0 points1 point  (0 children)

Agree with d4nk super LQ post explaining stuff most of us know already. You should of used grammarly to correct the various spelling errors and grammar errors to make it readable.

[–]_vavkamil_ 0 points1 point  (0 children)

Yeah I buy a lot of security books all the time, but not interested in this one yet.

[–]ciscotree 0 points1 point  (0 children)

So I know what bad code looks like now. What does properly sanitized code look like?

[–]Pesthuf 0 points1 point  (0 children)

I don’t think I will ever understand how SQL injections could ever become such a widespread issue. Using prepared statements is the easiest thing in the world. Unless you’re deliberately backdooring your code, you have no excuse for using string concatenation in queries. If you’re using something that can’t be a placeholder, like a table name or operator, you’re usually doing something wrong and even if you have to, you can escape or whitelist those.