I think your interview questions are perfectly reasonable for any serious applicant to a high-end PHP job!
If the head hunters are talking [bleep] then they need to do their job and send you better candidates.
I don't think filtering input is a very good way to prevent SQL injection attacks, however, as the pattern/rule for what should be valid input for some fields -- such as this one, would be invalid as input for an SQL attack. :-)
PS
I hate using myspace, and much of why I hate it is exactly what you reference. It may be successful, but that doesn't make it good...
Last 10 Comments
1