thankx buddy for link.......as of now i am using stored procedure but i was looking for possibility of sql injection when all single quote ' from input are replaced with 2 single quote '' ......... or this simply block all sql injection