Security and compliance
Ensure data security and compliance with monitoring and change traceability
INSERT code that omits a column list, usually in mysterious ways and often without generating errors. Phil Factor demonstrates the problem, and advocates a 'defense-in-depth' approach to writing SQL, in order to avoid it. Read more(MAX) specification, which is a mistake too. Phil Factor explains the dangers and then offers a workaround for the problem, when… Read moreExecute(string) to execute a batch in a string, often assembled dynamically from user input. This technique is dangerous because the parameter values are injected before the statement is parsed by SQL Server, allowing an attacker to "tag on"… Read more