Click here to Skip to main content
15,907,001 members

Survey Results

Do you have plans to use the Entity Framework?   [Edit]

Survey period: 10 Nov 2008 to 17 Nov 2008

Having impedance mismatch problems? The Entity Framework could be the solution. Or maybe not. (Suggested by IdeaBlade)

OptionVotes% 
We already use it474.47
Definitely797.52
Maybe27325.98
Probably not17416.56
Definitely not706.66
I don't know what it is35633.87
It's not applicable to my work524.95



 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 7:40
Nemanja Trifunovic14-Nov-08 7:40 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 7:46
professionalJeremy Falcon14-Nov-08 7:46 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 8:07
Nemanja Trifunovic14-Nov-08 8:07 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:21
professionalJeremy Falcon14-Nov-08 8:21 
GeneralRe: How is afraid of the big bad SQL? Pin
PedroMC12-Nov-08 1:55
PedroMC12-Nov-08 1:55 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic12-Nov-08 8:22
Nemanja Trifunovic12-Nov-08 8:22 
GeneralRe: How is afraid of the big bad SQL? Pin
PedroMC12-Nov-08 22:56
PedroMC12-Nov-08 22:56 
GeneralRe: How is afraid of the big bad SQL? [modified] Pin
Nemanja Trifunovic13-Nov-08 6:10
Nemanja Trifunovic13-Nov-08 6:10 
PedroMC wrote:
Sanitizing data is enough to avoid SQL injections. That has always been available and it usually is trivial to do.


Actually, it is far from trivial. The only 100% reliable way to do this is to have exactly the same SQL parser as your DBMS, run your assembled queries through it and make sure that it does whatever you intended it to do.

Parameterized queries are the only practical protection from SQL injections.

PedroMC wrote:
Not every, but SQL is far from being the only (e.g. buffer overflows).


That's a very good observation. Programming techniques that introduce stack overflow are today recognized as dangerous and good C compilers even emit warnings for them. Assembling SQL queries "on fly" and including users' input in them is exactly one such technique (except that it is much easier to exploit) and should be avoided.


modified on Thursday, November 13, 2008 12:23 PM

GeneralRe: How is afraid of the big bad SQL? Pin
PedroMC13-Nov-08 23:41
PedroMC13-Nov-08 23:41 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 4:01
Nemanja Trifunovic14-Nov-08 4:01 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:15
professionalJeremy Falcon14-Nov-08 8:15 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 8:18
Nemanja Trifunovic14-Nov-08 8:18 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:23
professionalJeremy Falcon14-Nov-08 8:23 
GeneralRe: How is afraid of the big bad SQL? Pin
PedroMC14-Nov-08 11:35
PedroMC14-Nov-08 11:35 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:08
professionalJeremy Falcon14-Nov-08 8:08 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:12
professionalJeremy Falcon14-Nov-08 8:12 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 9:06
Nemanja Trifunovic14-Nov-08 9:06 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 9:48
professionalJeremy Falcon14-Nov-08 9:48 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 10:15
Nemanja Trifunovic14-Nov-08 10:15 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 10:33
professionalJeremy Falcon14-Nov-08 10:33 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:03
professionalJeremy Falcon14-Nov-08 8:03 
GeneralRe: How is afraid of the big bad SQL? Pin
Nemanja Trifunovic14-Nov-08 8:13
Nemanja Trifunovic14-Nov-08 8:13 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon14-Nov-08 8:22
professionalJeremy Falcon14-Nov-08 8:22 
GeneralRe: How is afraid of the big bad SQL? Pin
Jeremy Falcon11-Nov-08 6:08
professionalJeremy Falcon11-Nov-08 6:08 
GeneralRe: How is afraid of the big bad SQL? Pin
Thomas Weller11-Nov-08 6:56
Thomas Weller11-Nov-08 6:56 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.