Hi group,

I've got a web site in .Net. Waauw.
The users are able to enter SQL statements in the address bar, eg DELETE FROM tblOrders....not so nice eh.

I know there's a statement that protects the db from this...but what is it?

Any ideas what I'm mumbling about?

TIA

VS