On Nov 27, 2011, at 12:37 AM, jackie sparks wrote:
> Miscoded and rouge plugins, I'm talking about plugins that allow SQL injections. Not plugins that actually look like they have bad intent. 

I'm confused. Isn't SQL injection mostly destructive, and not for accessing information? Doesn't matter if a table's data is encrypted dropping a table still drops a table.

Of course I don't consider myself a security expert so maybe I'm wrong about this and it is reasonable to use SQL injection to access data?

