I mean SQL injection is such an easy known mitigation yet is still on the OWASP top 10 even after so many years.
I mean SQL injection is such an easy known mitigation yet is still on the OWASP top 10 even after so many years.
; delete from comments where id = 29544262 */--
sanitize their inputs....still there?
Edit: I apologize for getting 'sanitation' wrong. Don't do it.
Sanitization is a defence of last resort when you simply can't separate code and data. Usually used for user content on the web since HTML has no formal mechanism to separate code and data because the angled brackets that do this separation are also valid user input.
But databases do have a way to separate the query from the data. Parametize your queries.
For anyone confused about why "sanitizing your inputs" isn't the right approach, please read (shameless self-promotion, but I think the concept is important): https://benhoyt.com/writings/dont-sanitize-do-escape/