Viewing 15 posts - 23,131 through 23,145 (of 49,552 total)
Lexa (10/1/2011)
GilaMonster (10/1/2011)
Lexa (10/1/2011)
codebyo (10/1/2011)
'sp_executesql' will do that for you.
codebyo, what exactly do you mean by it will do that for you? If a '; drop table --' command...
Gail Shaw
Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability
October 1, 2011 at 1:38 pm
codebyo (10/1/2011)
GilaMonster (10/1/2011)
codebyo (10/1/2011)
I see many procedures that have checks for every parameter passed instead of doing as advised here in this topic. 🙂
Defend in depth. Check parameters and use...
Gail Shaw
Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability
October 1, 2011 at 1:28 pm
declare @tmp table (userid int, finalplace int, totalpoints int)
insert into @tmp (userid, finalplace, totalpoints)
SELECT @portalid UNION ALL
SELECT @venueid
SELECT @fromdate
SELECT @todate
SELECT @regionid
What are you trying to do here? You've defined a...
Gail Shaw
Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability
October 1, 2011 at 1:27 pm
ashkan siroos (10/1/2011)
@GilaMonster: could you please describe more?
I could, or you could use a search engine and do some reading. There's a lot out there, far more than I could...
Gail Shaw
Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability
October 1, 2011 at 1:24 pm
giontech (10/1/2011)
Gail Shaw
Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability
October 1, 2011 at 12:30 pm
codebyo (10/1/2011)
I see many procedures that have checks for every parameter passed instead of doing as advised here in this topic. 🙂
Defend in depth. Check parameters and use parameterisation properly.
Gail Shaw
Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability
October 1, 2011 at 12:26 pm
Lexa (10/1/2011)
codebyo (10/1/2011)
'sp_executesql' will do that for you.
codebyo, what exactly do you mean by it will do that for you? If a '; drop table --' command is passed,...
Gail Shaw
Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability
October 1, 2011 at 12:25 pm
ashkan siroos (9/30/2011)
Gail Shaw
Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability
October 1, 2011 at 12:17 pm
Jack Corbett (10/1/2011)
I just hope I can honor that award the way that all the MVP's...
Gail Shaw
Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability
October 1, 2011 at 10:57 am
None of the databases at all?
Not there, or just missing the +?
Check the drives, make sure the drive with the database files is still accessible.
Gail Shaw
Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability
October 1, 2011 at 9:34 am
Yes. If you don't parameterise the statement. You can still write un-parameterised dynamic SQL with sp_executesql. The use of sp_executesql alone won't protect you, proper parameterisation and the use of...
Gail Shaw
Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability
October 1, 2011 at 8:08 am
Evil Kraig F (10/1/2011)
Gail Shaw
Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability
October 1, 2011 at 8:04 am
Lowell (9/30/2011)
Gail Shaw
Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability
October 1, 2011 at 4:00 am
Always.
Gail Shaw
Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability
September 30, 2011 at 6:12 pm
Drop index 9 on table 'Auth_Primary' and recreate it.
Gail Shaw
Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability
September 30, 2011 at 5:42 pm
Viewing 15 posts - 23,131 through 23,145 (of 49,552 total)