Hi @all!
I have invested some time to think about detecting & preventing SQL Injection attacks to web-applications.
Here's a paper approaching the same problem from another angle.
http://glide.stanford.edu/yichen/paper.pdf
cheers
\a
-- Andrew Simmons MessageLabs Security Team
MessageLabs - Be Certain