Click here to Skip to main content
15,907,236 members

Survey Results

Do you have plans to use the Entity Framework?   [Edit]

Survey period: 10 Nov 2008 to 17 Nov 2008

Having impedance mismatch problems? The Entity Framework could be the solution. Or maybe not. (Suggested by IdeaBlade)

OptionVotes% 
We already use it474.47
Definitely797.52
Maybe27325.98
Probably not17416.56
Definitely not706.66
I don't know what it is35633.87
It's not applicable to my work524.95



 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 8:18
Nemanja Trifunovic14-Nov-08 8:18 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:23
professionalJeremy Falcon14-Nov-08 8:23 
GeneralRe: How is afraid of the big bad SQL? Pin
PedroMC14-Nov-08 11:35
PedroMC14-Nov-08 11:35 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:08
professionalJeremy Falcon14-Nov-08 8:08 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:12
professionalJeremy Falcon14-Nov-08 8:12 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 9:06
Nemanja Trifunovic14-Nov-08 9:06 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 9:48
professionalJeremy Falcon14-Nov-08 9:48 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 10:15
Nemanja Trifunovic14-Nov-08 10:15 
Jeremy Falcon wrote:
And of course, he's right.


And of course, he never bothered to read this link from the post with the highest ranking[^] (pay special atention to the Unicode part). The conclusion:

This paper proves that an application may be vulnerable to SQL Injection
attacks, even though it does proper input validation before calling a stored procedure,
in contrast to conventional wisdom that input validation is sufficient to protect an application
against SQL Injection.


Jeremy Falcon wrote:
So, assuming all fields are validated, then that will work.


Repeating myself again...

1) It is not possible to reliably validate fields if they are going into an SQL statement
2) Even if it was possible, it is too much work and no-one is doing it

From 1) and 2) => Concatinating strings to make SQL queries is evil. Never, ever do that. Or if you do, don't say I didn't warn you Wink | ;)


GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 10:33
professionalJeremy Falcon14-Nov-08 10:33 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:03
professionalJeremy Falcon14-Nov-08 8:03 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 8:13
Nemanja Trifunovic14-Nov-08 8:13 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:22
professionalJeremy Falcon14-Nov-08 8:22 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon11-Nov-08 6:08
professionalJeremy Falcon11-Nov-08 6:08 
GeneralRe: How is afraid of the big bad SQL? Pin
Thomas Weller11-Nov-08 6:56
Thomas Weller11-Nov-08 6:56 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon11-Nov-08 9:47
professionalJeremy Falcon11-Nov-08 9:47 
GeneralRe: How is afraid of the big bad SQL? Pin
Thomas Weller11-Nov-08 22:07
Thomas Weller11-Nov-08 22:07 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:43
professionalJeremy Falcon14-Nov-08 8:43 
GeneralRe: How is afraid of the big bad SQL? Pin
Thomas Weller16-Nov-08 23:37
Thomas Weller16-Nov-08 23:37 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon17-Nov-08 5:52
professionalJeremy Falcon17-Nov-08 5:52 
GeneralRe: How is afraid of the big bad SQL? Pin
Thomas Weller17-Nov-08 6:03
Thomas Weller17-Nov-08 6:03 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon17-Nov-08 7:47
professionalJeremy Falcon17-Nov-08 7:47 
GeneralRe: How is afraid of the big bad SQL? Pin
Paul Conrad14-Nov-08 11:52
professionalPaul Conrad14-Nov-08 11:52 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon16-Nov-08 9:56
professionalJeremy Falcon16-Nov-08 9:56 
GeneralRe: How is afraid of the big bad SQL? Pin
PedroMC12-Nov-08 2:29
PedroMC12-Nov-08 2:29 
GeneralRe: How is afraid of the big bad SQL? Pin
Thomas Weller12-Nov-08 5:22
Thomas Weller12-Nov-08 5:22 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.