HN
Hacker News
Top
New
Best
Ask
Show
Jobs
Comment by k_bx | Hacker News Reader
Full thread
k_bx
·
> SQL-injection
> NASDAQ
View on HN
sirsar
·
Sanitizing your inputs is apparently even harder than salting and hashing your passwords, something even the big-name companies tend to mess up.
Sigh.
PlaneSploit
·
Little Bobby Tables, we call him.
dpatru
·
http://xkcd.com/327/
k_bx
·
You don't even need to sanitize them, actually.
sirsar
·
That's true. For example in Python, you declare the query as "Select * from a where b=? and c=d" and then put a tuple (z,) to specify b.
It's something the NYSE should get "hip" to.
tracker1
·
That was my first note as well.. imho, they deserved to get hacked.
Reply on news.ycombinator.com