Some sites are affected by sql injection.
Here i will show you some symbols and keyword which must not be in the user inputs.
For that you must have to validate input of user at the both end. using javascript
and from the code-behing page.
List of blacklisted symbols:
--
;--
;
/*
*/
@@
@
char, nchar, varchar, nvarchar, alter, begin, cast, create, cursor, declare, delete, drop, end, exec, execute, fetch, insert, kill, open, select, sys, sysobjects, syscolumns, table, update