Re: Protection from SQL injection

Поиск
Список
Период
Сортировка
От Jaime Casanova
Тема Re: Protection from SQL injection
Дата
Msg-id c2d9e70e0804261431y6f25f783hf5d43121749b7aba@mail.gmail.com
обсуждение исходный текст
Ответ на Re: Protection from SQL injection  ("Thomas Mueller" <thomas.tom.mueller@gmail.com>)
Ответы Re: Protection from SQL injection  ("Thomas Mueller" <thomas.tom.mueller@gmail.com>)
Список pgsql-sql
On Sat, Apr 26, 2008 at 1:19 PM, Thomas Mueller
<thomas.tom.mueller@gmail.com> wrote:
> Hi,
>
> >  > The 'ALLOW_LITERALS NONE' mode is enabled by the developer itself, or
> >  > by an administrator.
> >  then it solves nothing...
> >  what if the developer never SET ALLOW_LITERALS NONE
>
> As I have said, the 'ALLOW_LITERALS NONE' mode is enabled by the
> developer itself, or by an administrator. The developer may be lazy,
> but the administrator can enforce this policy.
>

but can't the developer allow literals again?

> >  maybe i can inject "select * from tab where intcol = intcol; set
> >  allow_literals all; add any query you want"
>
> How do you inject this? How would the application looks like where
> this can be injected?
>

ok... point taken

-- 
regards,
Jaime Casanova
Soporte de PostgreSQL
Guayaquil - Ecuador
Cel. (593) 087171157


В списке pgsql-sql по дате отправления:

Предыдущее
От: "Thomas Mueller"
Дата:
Сообщение: Re: Protection from SQL injection
Следующее
От: Thomas Kellerer
Дата:
Сообщение: Re: Protection from SQL injection