Comment by rpigab

2 months ago

Between around 2005 and 2011 in France, if a child was born and parents Mr Bar and Mrs Baz wanted to transmit both of their last names, he or she had to be named "Foo Bar--Baz". No, that's not a typo, that's two hyphens. Check out "Circulaire du 6 décembre 2004 relative au nom de famille" if you don't believe me.

Yes, the people in charge probably didn't think or know of SQL comments. However, it worked well as long as input is sanitized and not concatenated, which is often the case using modern frameworks or common sense.

However, nowadays, we just put a WAF in front of everything, it's cheaper that way because common sense is hard to come by. People like Foo Bar--Baz still exist, and unless they've had their name changed, they're sometimes running into extremely wierd issues in the web software they're using.