• Definitely read all you can on dynamic sql, not just for security but performance too. One thing you can do quickly, check for semi colons - the most common hack is to add a semi colon to the end.

    Andy

    http://www.sqlservercentral.com/columnists/awarren/