<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: SQLAuthority News &#8211; SQL Injection &#8211; SQL Joke, SQL Humor, SQL Laugh</title>
	<atom:link href="http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/</link>
	<description>Personal Notes of Pinal Dave</description>
	<lastBuildDate>Sun, 12 Feb 2012 09:22:39 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Shatrughna Kumar</title>
		<link>http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/#comment-160967</link>
		<dc:creator><![CDATA[Shatrughna Kumar]]></dc:creator>
		<pubDate>Tue, 23 Aug 2011 11:27:18 +0000</pubDate>
		<guid isPermaLink="false">http://sqlauthority.wordpress.com/?p=1350#comment-160967</guid>
		<description><![CDATA[Good one.
I really enjoyed it.]]></description>
		<content:encoded><![CDATA[<p>Good one.<br />
I really enjoyed it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Madhivanan</title>
		<link>http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/#comment-70829</link>
		<dc:creator><![CDATA[Madhivanan]]></dc:creator>
		<pubDate>Fri, 14 May 2010 13:01:21 +0000</pubDate>
		<guid isPermaLink="false">http://sqlauthority.wordpress.com/?p=1350#comment-70829</guid>
		<description><![CDATA[Search for SQL injection in google/bing]]></description>
		<content:encoded><![CDATA[<p>Search for SQL injection in google/bing</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Madhivanan</title>
		<link>http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/#comment-70828</link>
		<dc:creator><![CDATA[Madhivanan]]></dc:creator>
		<pubDate>Fri, 14 May 2010 13:00:31 +0000</pubDate>
		<guid isPermaLink="false">http://sqlauthority.wordpress.com/?p=1350#comment-70828</guid>
		<description><![CDATA[Thats cool. I have seen lot of people referring that

Here is an approach with derived table that avoids sql injection
http://beyondrelational.com/blogs/madhivanan/archive/2010/05/14/derived-table-new-approach-to-avoid-sql-injection.aspx]]></description>
		<content:encoded><![CDATA[<p>Thats cool. I have seen lot of people referring that</p>
<p>Here is an approach with derived table that avoids sql injection<br />
<a href="http://beyondrelational.com/blogs/madhivanan/archive/2010/05/14/derived-table-new-approach-to-avoid-sql-injection.aspx" rel="nofollow">http://beyondrelational.com/blogs/madhivanan/archive/2010/05/14/derived-table-new-approach-to-avoid-sql-injection.aspx</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pramod</title>
		<link>http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/#comment-53899</link>
		<dc:creator><![CDATA[pramod]]></dc:creator>
		<pubDate>Tue, 21 Jul 2009 07:09:47 +0000</pubDate>
		<guid isPermaLink="false">http://sqlauthority.wordpress.com/?p=1350#comment-53899</guid>
		<description><![CDATA[hey really good one. Provides better understanding about the sql injection.]]></description>
		<content:encoded><![CDATA[<p>hey really good one. Provides better understanding about the sql injection.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: deeno</title>
		<link>http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/#comment-47548</link>
		<dc:creator><![CDATA[deeno]]></dc:creator>
		<pubDate>Fri, 27 Feb 2009 00:03:53 +0000</pubDate>
		<guid isPermaLink="false">http://sqlauthority.wordpress.com/?p=1350#comment-47548</guid>
		<description><![CDATA[THAT was FUNNY!!!  If I had a nickel for every time I fixed a database where the only &#039;real&#039; problem was user inputs...  I would have more money than Bill Gates!]]></description>
		<content:encoded><![CDATA[<p>THAT was FUNNY!!!  If I had a nickel for every time I fixed a database where the only &#8216;real&#8217; problem was user inputs&#8230;  I would have more money than Bill Gates!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Iceman</title>
		<link>http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/#comment-46910</link>
		<dc:creator><![CDATA[Iceman]]></dc:creator>
		<pubDate>Thu, 19 Feb 2009 11:45:08 +0000</pubDate>
		<guid isPermaLink="false">http://sqlauthority.wordpress.com/?p=1350#comment-46910</guid>
		<description><![CDATA[Lol, even though i got it, Vaevictus explained it quite well]]></description>
		<content:encoded><![CDATA[<p>Lol, even though i got it, Vaevictus explained it quite well</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bala</title>
		<link>http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/#comment-45098</link>
		<dc:creator><![CDATA[Bala]]></dc:creator>
		<pubDate>Fri, 26 Dec 2008 11:21:15 +0000</pubDate>
		<guid isPermaLink="false">http://sqlauthority.wordpress.com/?p=1350#comment-45098</guid>
		<description><![CDATA[I enjoyed this actually this is a good one to realize about the validation of the inputs.]]></description>
		<content:encoded><![CDATA[<p>I enjoyed this actually this is a good one to realize about the validation of the inputs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paresh A Bhurke</title>
		<link>http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/#comment-43738</link>
		<dc:creator><![CDATA[Paresh A Bhurke]]></dc:creator>
		<pubDate>Thu, 16 Oct 2008 09:10:25 +0000</pubDate>
		<guid isPermaLink="false">http://sqlauthority.wordpress.com/?p=1350#comment-43738</guid>
		<description><![CDATA[Hi,

Good humour! 

Its simple. The name of the student which school entered in the application caused dropping of the table. Pupils name is 
&quot;Robert&#039;);drop table students&quot;

Good one.


Paresh]]></description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Good humour! </p>
<p>Its simple. The name of the student which school entered in the application caused dropping of the table. Pupils name is<br />
&#8220;Robert&#8217;);drop table students&#8221;</p>
<p>Good one.</p>
<p>Paresh</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LN</title>
		<link>http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/#comment-43726</link>
		<dc:creator><![CDATA[LN]]></dc:creator>
		<pubDate>Thu, 16 Oct 2008 04:23:51 +0000</pubDate>
		<guid isPermaLink="false">http://sqlauthority.wordpress.com/?p=1350#comment-43726</guid>
		<description><![CDATA[Please elaborate more...]]></description>
		<content:encoded><![CDATA[<p>Please elaborate more&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Em</title>
		<link>http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/#comment-43707</link>
		<dc:creator><![CDATA[Em]]></dc:creator>
		<pubDate>Wed, 15 Oct 2008 06:09:55 +0000</pubDate>
		<guid isPermaLink="false">http://sqlauthority.wordpress.com/?p=1350#comment-43707</guid>
		<description><![CDATA[Hehe, good one!]]></description>
		<content:encoded><![CDATA[<p>Hehe, good one!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vaevictus</title>
		<link>http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/#comment-43683</link>
		<dc:creator><![CDATA[Vaevictus]]></dc:creator>
		<pubDate>Tue, 14 Oct 2008 02:48:33 +0000</pubDate>
		<guid isPermaLink="false">http://sqlauthority.wordpress.com/?p=1350#comment-43683</guid>
		<description><![CDATA[I&#039;ll take a whack at it...
imagine that the program used to enter new students in the database looked something like this:

sql = &quot; insert into students (firstname,lastname) VALUES (&#039;&quot; &amp; field1.value &amp; &quot;&#039;, &#039;&quot; &amp; field2.value &amp; &#039;&quot;)&quot;

normally, it&#039;d be fine, where fields &quot;bobby tables&quot; could be:
insert into students (firstname,lastname) VALUES (&#039;bobby&#039;,&#039;tables&#039;);

with the comic&#039;s first name provided, which is &quot;Robert&#039;); DROP TABLE Students; -- &quot;

which becomes:
insert into students (firstname,lastname) VALUES (&#039;Robert&#039;); DROP TABLE Students; --&#039;,&#039;tables&#039;);


in other words, the punctuation inserted causes the insert to become two statements and a comment.

in other words, insert into students, drop table students and comment out the rest.

so ... as the mother of bobby tables states in the comics,

&quot;AND I HOPE YOU&#039;VE LEARNED TO SANITIZE YOUR DATABASE INPUTS&quot;.

cheers.]]></description>
		<content:encoded><![CDATA[<p>I&#8217;ll take a whack at it&#8230;<br />
imagine that the program used to enter new students in the database looked something like this:</p>
<p>sql = &#8221; insert into students (firstname,lastname) VALUES (&#8216;&#8221; &amp; field1.value &amp; &#8220;&#8216;, &#8216;&#8221; &amp; field2.value &amp; &#8216;&#8221;)&#8221;</p>
<p>normally, it&#8217;d be fine, where fields &#8220;bobby tables&#8221; could be:<br />
insert into students (firstname,lastname) VALUES (&#8216;bobby&#8217;,'tables&#8217;);</p>
<p>with the comic&#8217;s first name provided, which is &#8220;Robert&#8217;); DROP TABLE Students; &#8212; &#8221;</p>
<p>which becomes:<br />
insert into students (firstname,lastname) VALUES (&#8216;Robert&#8217;); DROP TABLE Students; &#8211;&#8217;,'tables&#8217;);</p>
<p>in other words, the punctuation inserted causes the insert to become two statements and a comment.</p>
<p>in other words, insert into students, drop table students and comment out the rest.</p>
<p>so &#8230; as the mother of bobby tables states in the comics,</p>
<p>&#8220;AND I HOPE YOU&#8217;VE LEARNED TO SANITIZE YOUR DATABASE INPUTS&#8221;.</p>
<p>cheers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/#comment-43674</link>
		<dc:creator><![CDATA[Robert]]></dc:creator>
		<pubDate>Mon, 13 Oct 2008 15:27:00 +0000</pubDate>
		<guid isPermaLink="false">http://sqlauthority.wordpress.com/?p=1350#comment-43674</guid>
		<description><![CDATA[The name &#039;Bobby&#039; is a diminutive or &#039;nickname&#039; for Robert. 

The joke is that the parent named the child

Robert &#039;);DROP TABLE Students;

And so the database input actually executed the code DROP TABLE Students. 

Which the parent then is making fun of the school for not checking their data inputs. 

(I have no idea how you would import such a string so that it would actually run, but I gues there must be a way)]]></description>
		<content:encoded><![CDATA[<p>The name &#8216;Bobby&#8217; is a diminutive or &#8216;nickname&#8217; for Robert. </p>
<p>The joke is that the parent named the child</p>
<p>Robert &#8216;);DROP TABLE Students;</p>
<p>And so the database input actually executed the code DROP TABLE Students. </p>
<p>Which the parent then is making fun of the school for not checking their data inputs. </p>
<p>(I have no idea how you would import such a string so that it would actually run, but I gues there must be a way)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mahmoud Hakeem</title>
		<link>http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/#comment-43672</link>
		<dc:creator><![CDATA[Mahmoud Hakeem]]></dc:creator>
		<pubDate>Mon, 13 Oct 2008 10:42:23 +0000</pubDate>
		<guid isPermaLink="false">http://sqlauthority.wordpress.com/?p=1350#comment-43672</guid>
		<description><![CDATA[Can u explain more please?]]></description>
		<content:encoded><![CDATA[<p>Can u explain more please?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Maysam</title>
		<link>http://blog.sqlauthority.com/2008/10/12/sqlauthority-news-sql-injection-sql-joke-sql-humor-sql-laugh/#comment-43665</link>
		<dc:creator><![CDATA[Maysam]]></dc:creator>
		<pubDate>Sun, 12 Oct 2008 18:06:24 +0000</pubDate>
		<guid isPermaLink="false">http://sqlauthority.wordpress.com/?p=1350#comment-43665</guid>
		<description><![CDATA[I know what SQL Injection is but I don&#039;t get the relation between &quot;Little Bobby Tables&quot; and &quot;Drop Table Students&quot;. Would you explain it? I&#039;m sorry I&#039;m not a native English speaker and that might be my problem.]]></description>
		<content:encoded><![CDATA[<p>I know what SQL Injection is but I don&#8217;t get the relation between &#8220;Little Bobby Tables&#8221; and &#8220;Drop Table Students&#8221;. Would you explain it? I&#8217;m sorry I&#8217;m not a native English speaker and that might be my problem.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

