Answer Posted / srikant dwibedi
SQL Injection is he process of passing SQL code into an
application in a way that was not intended by the
application developer or it is a strategy for attacking
databases.
Example
An ASP page asks the user for a name and a password.
SELECT FROM users WHERE username="whatever" AND
password="mypassword".
It seems safe,but it is not. A user might enter somthing
like this 'OR 1>0....
when this is plugged into the SQL statewments the result
looks like this:
SELECT FROM users WHERE username="OR 1>0 " AND
password=" ";
This injectin comments out of the password portion of the
statement. It results in a list of all the names in the
users table. So any user could get into your system.
Is This Answer Correct ? | 3 Yes | 2 No |
Post New Answer View All Answers
What are the advantage of ado.net?
What is ado object model?
How to creating a SqlCommand Object?
What is a dynaset in access?
How to add an aggregate column?
What is ado.net in mvc?
Explain what are the steps to connect to a database?
What is the difference between SqlCommand and SqlCommandBuilder?
Do we use stored procedure in ADO.Net?
What do you know about ado.net's objects?
Why is stored procedure used in ado.net?
What is ado full form?
What do you mean by performing asynchronous operation using command object?
What is the purpose of using adodb?
What is dataadapter in ado.net?