Does the Bobby Tables effect present a threat to OS?
Hmm. Not sure.
Maybe if someones user name has a command but I doubt they can be connected to all the other users.
If I made an account with this username: `Robert'); DROP TABLE Users;--`
:O
OS should probably "sanitize their tables" to prevent trolls from doing this.
The trolls probably wouldn't have found out unless you made a question about it. -_-
@Preetha You need to sanitize our tables
"sanitize database inputs*"
im lost
lol
It's the about page.
How to avoid Bobby Tables There is only one way to avoid Bobby Tables attacks Do not create SQL statements that include outside data. Use parameterized SQL calls. http://bobby-tables.com/about.html
@CausticSyndicalist
It's called SQL injection, not "bobby tables", and it has existed long before xkcd even existed.
I know :/
I use "bobby tables" to make the post seem interesting, just as the bobby-tables.com site does.
Interesting..
Nope. Not at all. That is a SQL bug.
Join our real-time social learning platform and learn together with your friends!