"Doctor, it hurts when I do this." Don't do that!
"Doctor, it hurts when I do this." Don't do that!
My google search "Input sanitization" yielded these first 2 results
http://en.wikipedia.org/wiki/Secure_input_and_output_handlin...
2nd page (or more with a lesser screen), under "other solutions," this is the only line about parameterization: "In particular, to prevent SQL injection, parameterized queries (also known as prepared statements and bind variables) are excellent for improving security while also improving code clarity and performance." Everything else is about filtering, blacklisting, whitelisting, escaping.
http://www.esecurityplanet.com/browser-security/prevent-web-...
Discusses filtering as solution to HTML injection. Lastly discusses SQL injection, first recommending mysql_real_escape_string(), then in the second paragraph linking to another article about parameterization.
It's not, to an inexperienced developer (this is the web remember?), a clear-cut best practice from just "cursory research". It's a popular tech joke with obvious but non-optimal solutions.
What does the inexperienced developer learn from the new search terms?
I don't know why magically using different, non-standard words would prevent a developer from being inexperienced.
"I don't know why magically using different, non-standard words would prevent a developer from being inexperienced." It's really hard to give any response to this sort of flawless logic...