Xkcd Bobby Drop Tables

This work is licensed under a Creative Commons Attribution #, Who is Bobby Tables ?

From the webcomic xkcd.

School: Hi, this is your son’s school.

We’re having some computer trouble.

Mom: Oh, dear — Did he break something?


School: In a way.

Did you really name your son Robert’); DROP TABLE Students;–?


Mom: Oh.


Little Bobby Tables we call him.

School: Well, we’ve lost this year’s student records.

I hope you’re happy.

From the evidence that Mrs.

From the evidence that Mrs. Roberts has two children, a daughter named Elaine, and a younger son named Bobby (presumably Little Bobby Tables aka "Robert'); DROP TABLE students;–"), we can assume that she is the same mother from 327: Exploits of a Mom.

Of course, the title text here explains that Elaine is only her middle name (assuming.

— Input: Robert’); DROP TABLE students; — school=> INSERT INTO students VALUES (‘Robert’); DROP TABLE students; –‘); INSERT 0 1 DROP TABLE The SQL injection here is the result of the name of the student terminating the statement and including a separate DROP TABLE command; the two dashes at the end of the input are intended to comment out.

Immortalized by “Little Bobby Drop Tables ” in XKCD 327, SQL injection (SQLi) was first discovered in 1998, yet continues to plague web applications across the internet.

Even the OWASP Top Ten lists.

Explanation [].


Roberts receives a call from her son’s school.

The caller, likely one of the school’s administrators, asks if she really named her son Robert’); DROP TABLE Students;–, a rather unusual name.

[citation needed] Perhaps surprisingly, Mrs.

Roberts responds in the affirmative, claiming that she uses the nickname “Little Bobby Tables.

“As the full name is read into the school’s.

