J
Johnny Luner
I read an article about SQL Script Injection, it teaches me how to prevent
it using old fashion ASP:
String: p_strUsername = Replace(Request.Form("txtUsername"), "'", "''")
INT: p_lngID = CLng(Request("ID"))
How about C# in .NET? Any suggestions?
Thanks.
it using old fashion ASP:
String: p_strUsername = Replace(Request.Form("txtUsername"), "'", "''")
INT: p_lngID = CLng(Request("ID"))
How about C# in .NET? Any suggestions?
Thanks.