...i z tego powodu należy poświęcać temu tematowi należną uwagę: Giving SQL Injection the Respect it Deserves.
(...) The SDL is very specific about what do here, there are three requirements - they are requirements not recommendations, which means you must do the following coding requirements and defenses: * Use SQL Parameterized Queries * Use Stored Procedures * Use SQL Execute-only Permission (...)To są na prawdę trzy proste kroki. W dodatku bardzo skuteczne.