SQL Macros with no SQL Injection !

preview_player
Показать описание
SQL Macros let you change the contents of SQL as it is parsed by the database engine. But if we are changing the text of the SQL, and that change might be done based on user provided parameters, are we not just opening the door very very wide open and inviting Mr SQL Injection to the party?


Subscribe for new tech videos every week



Are you serious? A free Oracle database forever ?!?!?!?! Hell yeah!!!




Music: Night Owl (Broke For Free)
, Dyalla

#sqlmacro #sqlinjection #security
Рекомендации по теме
Комментарии
Автор

Can resolving the null parameter be made fatal?

berndeckenfels
welcome to shbcf.ru