It's my first time developing using MVC and I want to make it secure.
When I use HtmlEncode it converts the String to the equivalent HTML String.
The user can enter in the search for example ali' or ali-- and they exist in my database. How to control my search and login from SQL injection please?
Also any tutorial or best practice to prevent script injection?
See Question&Answers more detail:
os 与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…