Figmo2 wrote:
Am I right in assuming that this should be adequate protection?
You're using a parameterised query, so you should be OK on that front. However, take a look at http://msdn.microsoft.com/en-us/library/ms179859.aspx[^] for some more "magic characters" that might appear in your search string, and give unexpected results.
Server and Network Monitoring