Forum Replies Created

Viewing 15 posts - 23,131 through 23,145 (of 49,552 total)

  • RE: SQL Injection and sp_executesql

    Lexa (10/1/2011)


    GilaMonster (10/1/2011)


    Lexa (10/1/2011)


    codebyo (10/1/2011)


    'sp_executesql' will do that for you.

    codebyo, what exactly do you mean by it will do that for you? If a '; drop table --' command...

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass
  • RE: SQL Injection and sp_executesql

    codebyo (10/1/2011)


    GilaMonster (10/1/2011)


    codebyo (10/1/2011)


    I see many procedures that have checks for every parameter passed instead of doing as advised here in this topic. 🙂

    Defend in depth. Check parameters and use...

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass
  • RE: Help with SQL query and Stored Procedure

    declare @tmp table (userid int, finalplace int, totalpoints int)

    insert into @tmp (userid, finalplace, totalpoints)

    SELECT @portalid UNION ALL

    SELECT @venueid

    SELECT @fromdate

    SELECT @todate

    SELECT @regionid

    What are you trying to do here? You've defined a...

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass
  • RE: problem in membership design- UserName as a foreign key or userID

    ashkan siroos (10/1/2011)


    @GilaMonster: could you please describe more?

    I could, or you could use a search engine and do some reading. There's a lot out there, far more than I could...

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass
  • RE: Could not find database ID 14

    giontech (10/1/2011)


    By the way, the database files are still in the MSSQL Data Folder, it was like 30 minutes past already since I clicked to take offline, obviously there was...

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass
  • RE: SQL Injection and sp_executesql

    codebyo (10/1/2011)


    I see many procedures that have checks for every parameter passed instead of doing as advised here in this topic. 🙂

    Defend in depth. Check parameters and use parameterisation properly.

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass
  • RE: SQL Injection and sp_executesql

    Lexa (10/1/2011)


    codebyo (10/1/2011)


    'sp_executesql' will do that for you.

    codebyo, what exactly do you mean by it will do that for you? If a '; drop table --' command is passed,...

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass
  • RE: problem in membership design- UserName as a foreign key or userID

    ashkan siroos (9/30/2011)


    I'm designing a database for a membership issue. I have checked some other popular designs for membership and I saw some people used username(nvarchar(200)) as foreignkey in their...

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass
  • RE: Are the posted questions getting worse?

    Jack Corbett (10/1/2011)


    Hey guys I got some really cool news today. I was awarded MVP status!

    I just hope I can honor that award the way that all the MVP's...

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass
  • RE: Could not find database ID 14

    None of the databases at all?

    Not there, or just missing the +?

    Check the drives, make sure the drive with the database files is still accessible.

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass
  • RE: SQL Injection and sp_executesql

    Yes. If you don't parameterise the statement. You can still write un-parameterised dynamic SQL with sp_executesql. The use of sp_executesql alone won't protect you, proper parameterisation and the use of...

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass
  • RE: inserting data into views

    Evil Kraig F (10/1/2011)


    Now, as to triggering on a view... I'll get back to you on that Lowell. I've both never thought to think about doing that, and had...

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass
  • RE: inserting data into views

    Lowell (9/30/2011)


    Kraig you are alluding to the possiblity of an INSTEAD OF trigger on the view, to handle the logic of insertin/updating tables that are joined in the view,...

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass
  • RE: SQL Server Stack Dump

    Always.

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass
  • RE: SQL Server Stack Dump

    Drop index 9 on table 'Auth_Primary' and recreate it.

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass

Viewing 15 posts - 23,131 through 23,145 (of 49,552 total)