Bullet-Proof SQL Injection Defense

Post by Goatboy on Tue Mar 29, 2011 2:59 pm
Found this on HackerNews:


View the source, and prepare to be amazed by the best SQL Injection defense EVAR.

Not sure what's worse. The fact that this is in a production environment, or that I am not at all surprised it is in a production environment.
Re: Bullet-Proof SQL Injection Defense

Post by OnlyHuman on Tue Mar 29, 2011 3:15 pm
Well you said it yourself. It's bullet proof. No way around that. And they left select unfiltered, which is good... for... admins. You know, because they may need to select something, from another non-filtered source, such as information_schema. But, that's just taking a guess at the database they're using, based solely on the things they did choose to filter.


WTF? I swear that wasn't filtered a second ago. Eyes are playing tricks on me. Just have to resort to more nefarious methods of circumventing that security, such as disabling JavaScript or something.
