Dailydave mailing list archives

Re: From blackbox to grey-box during Web App tests


From: "Thomas Ptacek" <tqbf () matasano com>
Date: Sun, 14 Oct 2007 08:56:18 -0500

        Why don't more people just use Parameterized Stored Proceedures?  Is it
because there are implimentation issues or because people don't know
about them? Whats your opinion?

I wonder that too. Also, why don't people just not write integer overflows?

With the snark bit cleared, I'll point out: lots of projects use
stored procedures, but have some patches of functionality (like query
builders) that are easiest to write with raw SQL.

-- 
---
Thomas H. Ptacek // matasano security
read us on the web: http://www.matasano.com/log
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: