Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, I'm not making a straw man, I'm pointing out that "SQL Injection" is very vague, and attempted SQL injection even more so.

There is a huge gulf between checking for access and abusing access.



And that's why we have DAs, grand juries, judges, and juries. If someone gets brought up on charges for literally putting an apostrophe in a form field on a website the system has failed because there's no clear intent to perform an attack of any kind in that case. When that happens, let's talk.


That is exactly what happens.


is it? Citation please.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: