Posted by Ivan Marsh on 05/15/07 15:24
On Fri, 11 May 2007 23:02:45 +0000, Gordon Burditt wrote:
>>I set the default user for my connection to the read-only account and
>>have to purposefully change the account being used if I want to do
>>anything other than just read.
>>
>>You can't inject SQL if the account you're using doesn't have rights to
>>write to the database.
>
> There are plenty of people who would love to inject
> select * from credit_card_account_list;
> even if the account you're using has no rights to write to the database.
Obviously I was speaking of injections to cause data corruption.
Anyone stupid enough to use credit_card_account_list as a table name
deserves to go out of business.
Navigation:
[Reply to this message]
|