Live source code: http://github.com/costan/security_in_webapps_slides
2) Don't escape your SQL, use parameterized queries
Live source code: http://github.com/costan/security_in_webapps_slides