• u should use perameterized dynamic sql to get away from the sql injection