Wednesday, 23 March 2011

Garbage in, Garbage out

Why you should not accept data from users into a DB without checking it.

Exhibit A: "select manufacturer"

<OPTION value="FUJITSO">FUJITSO</OPTION>

<OPTION value="FUJITSU">FUJITSU</OPTION>

<OPTION value="FUJITSU SIEMENS">FUJITSU SIEMENS</OPTION>

<OPTION value="FUJITSU-SIEMEN">FUJITSU-SIEMEN</OPTION>

<OPTION value="FUJITSU-SIEMENES">FUJITSU-SIEMENES</OPTION>

<OPTION value="FUJITSU-SIEMENS">FUJITSU-SIEMENS</OPTION>

No comments:

Feeling Pumped!

Having just had a day without power, and then going round the site to check everything came back online correctly (including services such a...