From: Chris Pine Date: 2003-02-02T08:30:22+09:00 Subject: Re: String#+ ----- Original Message ----- > I was generating SQL statements at the time. Hopefully nothing like this: sql = "select * from foo where key = '" + myvar + "'" If you encourage your students to do that, sooner or later their databases will get hacked :-) ---------------------------- This isn't part of any tutorial; it's for my own stuff. In any case, I don't see how you can say that the above code will eventually get the database hacked. Clearly, it depends on where 'myvar' is coming from. These are not strings from the cgi post hash! (I'm not evaling any strings from the user, either. :) 'myvar' could come from trusted session data, or from a previous query... Perhaps I'm not understanding you. Chris