Alex Rivera | Logout

How can I avoid SQL injection attacks in my ASP.NET application?

Asked 2008-11-20T11:49:07.423
22

I need to avoid being vulnerable to SQL injection in my ASP.NET application. How might I accomplish this?

Edit
Report

2 Answers

1

As others have said, don't concatenate user input to create dynamic sql statements; always use parameterized SQL when using dynamic SQL. However I will point out that this rule also applies when creating dynamic sql inside of a stored proc. This fact is something people often overlook. They think they are safe because they are "using stored procedures."

answered 2009-08-06T19:58:18.127
-3

Understand what exactly SQL Injection is and then never write anything that is vulnerable to it.

answered 2009-08-06T07:48:54.660

Your Answer