SQl注入的防御
摘要:
1.使用参数化的过滤性语句Prepared Statements (Parameterized Queries)Parameterized queries force the developer to first define all the SQL code, andthen pass in each parameter to the query later. This coding style allows thedatabase to distinguish between code and data, regardless of what user input issupplied.P 阅读全文
posted @ 2012-07-16 06:26 Songhan 阅读(367) 评论(0) 推荐(0) 编辑