Protect against SQL Injection by whitelisting |
 |
EXPERT RESPONSE FROM: Steven Andres

|
 |
|


|
| > |
QUESTION POSED ON: 23 March 2007
OK, admittedly the best practice for guarding against SQL Injection attacks is to white-list acceptable characters. However, given that knowledge is power, is there a comprehensive list of special characters (such as the single-quote or double-hyphen) available for SQL Server? I have done a ton of searches and can't seem to find one (I did find the reserved words).
|
|
To continue reading for free, register below or login
To read more you must become a member of SearchSQLServer.com
|
|
');
// -->

|
|
 |

 |
 |
Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and
answer pairs from more than 250 TechTarget industry experts.
|
 |
 |
 |
|
 |
 |
 |
|
 |
|
 |