Constrain Input. You should validate all input to your ASP.NET applications for type, length, format, and range. ...
Use Parameters with Stored Procedures. Using stored procedures does not necessarily prevent SQL injection. ...
Use Parameters with Dynamic SQL.