Don't DROP our data
JoC
July 6th, 2007 11:56am
That is an amusing error message. Kinda just asking for somebody to turn off javascript and enter some evil SQL.
"Hudson Valley Federal Credit Union's online banking enrollment asks the typical security questions."
I work with bank type software/security. This place wouldnt pass any of the federal (enron like) guidelines on security. Oh my god.
Also, normally if you encounter any invalid characters like
"'", you are supposed to fail out, that and use prepared statements.
I thought you just used parameterized sprocs and called it a day?
JoC
July 6th, 2007 2:38pm