SQL Injection Protection-repeat old issues (original)

Source: Internet
Author: User

You don't need to worry about this issue in current development. The general ORM can help you solve it.

If you want to write it by yourself, the parameter value conversion method is generally used to solve the problem. Some class problems rarely occur during development.

However, in some special cases, you must use the SQL spelling method. Therefore, it is inevitable to pay attention to the SQL Injection Protection problem.

The general considerations are as follows:

In SQL, strings, numbers, and dates are commonly used.

For numbers: Check whether the number is correct before splicing. If not, an error is returned.

String: It is okay to replace single quotes with two in SQL. If SQL has the like clause, replace % with \ % and _ \_. Do not replace other characters.

Date type: It can also be processed like the statement type, but an error will be reported during SQL Execution. It is best to judge before merging.

 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.