<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Preventing SQL Injection with MySQL and PHP</title>
	<atom:link href="http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/</link>
	<description>Technical Articles, Musings and Opinions from Tech-Evangelist</description>
	<lastBuildDate>Sun, 29 Jan 2012 19:09:23 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Web Developers, Beware, Your website might be hacked &#171; kenyandeveloper</title>
		<link>http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/comment-page-1/#comment-23889</link>
		<dc:creator>Web Developers, Beware, Your website might be hacked &#171; kenyandeveloper</dc:creator>
		<pubDate>Thu, 12 Jan 2012 18:10:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/#comment-23889</guid>
		<description>[...] How To prevent MySQL injection  http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/ [...]</description>
		<content:encoded><![CDATA[<p>[...] How To prevent MySQL injection  http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/ [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Prevenindo SQL Injection com PHP &#124; Flávio Studart</title>
		<link>http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/comment-page-1/#comment-23866</link>
		<dc:creator>Prevenindo SQL Injection com PHP &#124; Flávio Studart</dc:creator>
		<pubDate>Wed, 21 Dec 2011 18:12:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/#comment-23866</guid>
		<description>[...] http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/" rel="nofollow">http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Doogie</title>
		<link>http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/comment-page-1/#comment-23861</link>
		<dc:creator>Doogie</dc:creator>
		<pubDate>Wed, 14 Dec 2011 22:47:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/#comment-23861</guid>
		<description>Hi Tibob

You missed the details in the explanation. &quot;If you are wondering what the trailing ‘i’ is following each word in the array, it is required to make the preg_replace replacements case insensitive.&quot;  So if you do it that way, the bad words are not case sensitive.</description>
		<content:encoded><![CDATA[<p>Hi Tibob</p>
<p>You missed the details in the explanation. &#8220;If you are wondering what the trailing ‘i’ is following each word in the array, it is required to make the preg_replace replacements case insensitive.&#8221;  So if you do it that way, the bad words are not case sensitive.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tibob</title>
		<link>http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/comment-page-1/#comment-23860</link>
		<dc:creator>Tibob</dc:creator>
		<pubDate>Wed, 14 Dec 2011 22:19:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/#comment-23860</guid>
		<description>Are the &quot;bad words&quot; case-sensitive? What if someone tries to inject, for example, UPDATE or Update instead of update? Do I have to add an uppercase version of each of the bad words to the list? 
Thanks for the article, by the way?</description>
		<content:encoded><![CDATA[<p>Are the &#8220;bad words&#8221; case-sensitive? What if someone tries to inject, for example, UPDATE or Update instead of update? Do I have to add an uppercase version of each of the bad words to the list?<br />
Thanks for the article, by the way?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim</title>
		<link>http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/comment-page-1/#comment-23269</link>
		<dc:creator>Jim</dc:creator>
		<pubDate>Mon, 12 Sep 2011 17:35:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/#comment-23269</guid>
		<description>Hey guys (and gals) what about PHP using MS SQL.  Is there a &quot;mysql_real_escape_string&quot; type string for use with MS SQL server backend?  I&#039;m getting hacked all the time!  :(</description>
		<content:encoded><![CDATA[<p>Hey guys (and gals) what about PHP using MS SQL.  Is there a &#8220;mysql_real_escape_string&#8221; type string for use with MS SQL server backend?  I&#8217;m getting hacked all the time!  <img src='http://www.tech-evangelist.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Password validation &#124; SeekPHP.com</title>
		<link>http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/comment-page-1/#comment-22738</link>
		<dc:creator>Password validation &#124; SeekPHP.com</dc:creator>
		<pubDate>Wed, 07 Sep 2011 11:24:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/#comment-22738</guid>
		<description>[...] &#8211; you should really read about SQL Injection. And I don&#8217;t mean the XKCD comics. In the following link you can find few examples and guidelines about how the make clear and safe query for both your [...]</description>
		<content:encoded><![CDATA[<p>[...] &#8211; you should really read about SQL Injection. And I don&#8217;t mean the XKCD comics. In the following link you can find few examples and guidelines about how the make clear and safe query for both your [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: matt</title>
		<link>http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/comment-page-1/#comment-22603</link>
		<dc:creator>matt</dc:creator>
		<pubDate>Wed, 03 Aug 2011 13:58:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/#comment-22603</guid>
		<description>@Tim - storing userdate with htmlentities parsed is STUPID. You should parse for html-entities on data output, and just store the raw data.

The issue with html entities is to prevent XSS attacks, and is a presentation layer issue.</description>
		<content:encoded><![CDATA[<p>@Tim &#8211; storing userdate with htmlentities parsed is STUPID. You should parse for html-entities on data output, and just store the raw data.</p>
<p>The issue with html entities is to prevent XSS attacks, and is a presentation layer issue.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Doogie</title>
		<link>http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/comment-page-1/#comment-22589</link>
		<dc:creator>Doogie</dc:creator>
		<pubDate>Tue, 26 Jul 2011 15:19:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/#comment-22589</guid>
		<description>Hi Steve

You can always add it if you want. We focused on the list of words that can lead to database damage.</description>
		<content:encoded><![CDATA[<p>Hi Steve</p>
<p>You can always add it if you want. We focused on the list of words that can lead to database damage.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve</title>
		<link>http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/comment-page-1/#comment-22587</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Tue, 26 Jul 2011 08:05:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/#comment-22587</guid>
		<description>Wouldn&#039;t it also be good to have &quot;select&quot; in your list of bad words?  Kill the string stone dead.</description>
		<content:encoded><![CDATA[<p>Wouldn&#8217;t it also be good to have &#8220;select&#8221; in your list of bad words?  Kill the string stone dead.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aadil</title>
		<link>http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/comment-page-1/#comment-22551</link>
		<dc:creator>Aadil</dc:creator>
		<pubDate>Wed, 20 Jul 2011 07:14:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech-evangelist.com/2007/11/05/preventing-sql-injection-attack/#comment-22551</guid>
		<description>Hi there...

Thanx for this.

Please advise how I could go about testing if this is actually working.

Thanx again.</description>
		<content:encoded><![CDATA[<p>Hi there&#8230;</p>
<p>Thanx for this.</p>
<p>Please advise how I could go about testing if this is actually working.</p>
<p>Thanx again.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

