Community

SQL Server Truncation Attacks

(Ronald van den Heetkamp) This article deals with a SQL injection attack that isn’t very well known, it is called a truncation attack. The idea is simple: a programmer develops a stored procedure and declares fixed field values. He could use a T-SQL function like: QUOTENAME or REPLACE to delimit or

Read More - Register for Free Membership