Where can I begin to avoid SQL Injection attacks?

asp.net c# entity-framework sql-injection

Question

I'm looking to make my site secure against SQL injection attacks. Does anyone have any good links to make the site secure against these types of attacks in an ASP.NET site (c#, web forms)?

EDIT:

I should point out at I am using the Entity Framework

1
7
2/6/2012 4:01:17 PM

Popular Answer

The first and best line of defense is to not use dynamic SQL.

Always use parameterized queries.

Take a look at the OWASP page about SQL Injection.

14
2/6/2012 3:53:27 PM


Related Questions





Related

Licensed under: CC-BY-SA with attribution
Not affiliated with Stack Overflow
Licensed under: CC-BY-SA with attribution
Not affiliated with Stack Overflow