SQL injection/Countermeasures/Sanitizing/Partial

Partial sanitizing may affect any or more (unlisted here) of the following important syntax characters and result in them being encoded in some fashion, escaped, or removed entirely. In many circumstances, it is possible to craft injection queries without syntax characters, resulting in filter bypass and sometimes IDS evasion.

  • The space character (or all whitespace)
  • The single quote and double quote characters: ', "
  • The tag or "equals" comparative operators: <, >, and =
  • The comma character: ,
  • The parenthesis characters: ( and )