Post: It will not help
It will not help →
Posted Friday 27th June 2008 09:21 GMT
In Microsoft and HP tackle SQL-injection scourge
Microsoft, PHP, Perl have all had built-in functionality to avoid SQL injection for 10+ years now. Every single "corporate" developer I have met does not use it (except some of the perl-heads). Interestingly enough the non-corporate ones do.
Every time I work with a new team I have to teach them. And every time I leave a team which has started working properly using the so called prepared SQL statements and SQL variable substitution I find them to revert to the old injection-prone practices a few weeks later.
The truth is - developers do not care.
Me coat. The one which says "SQL injection is a self-inflicted problem".
Most read
Popular Whitepapers
- A Smart Path to Virtualization
Virtualization and Flexible Computing - Real-world server consolidation with Hyper-V
35 HP ProLiant DL385 servers onto 5 Dell PowerEdge M610 blade servers running Hyper-V - Business-Critical Applications
The Benefits of Intel Xeon Processors and Windows Server 2008 R2 for Business-Critical Apps - Virtualize at the speed of your business
The Dell guide to virtualization - A Cure for Server Sprawl
Dell Global Infrastucture Consulting helps DeKalb Medical - Staying committed to server refresh reduces cost
Can a server refresh help your company?