Reply to post:

Have I Been Pwned breach report email pwned entire firm's helldesk ticket system

Tom 7

Where possible I've always used stored procedures as the only way for the 'users' to access the DB, Most DBs have fairly comprehensive security that means an admin can prevent users from doing anything unless specifically allowed.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon