Doc #60398 [NEW]: mysql_real_escape_string description is wrong and decieving

From: Date: Sun, 27 Nov 2011 10:26:39 +0000
Subject: Doc #60398 [NEW]: mysql_real_escape_string description is wrong and decieving
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-7481@lists.php.net to get a copy of this message
From: Operating system: irrelevant PHP version: Irrelevant Package: Documentation problem Bug Type: Documentation Problem Bug description:mysql_real_escape_string description is wrong and decieving Description: ------------ --- From manual page: http://www.php.net/function.mysql-real-escape-string#refsect1- function.mysql-real-escape-string-description --- I am writing in account of the mysql_real_escape_string() description, which current phrasing is erroneous and decieving, leading thousands of PHP programmers to confusion and make them writing the code that actually _allows_ injection. It says at the moment --- This function must always (with few exceptions) be used to make data safe before sending a query to MySQL. --- Which is obviously wrong, as the function doesn't make data whatever "safe". And "few exceptions" statement is not an excuse as it explains nothing. Based on this very description, many people having an idea of injection protection limited to just "escape all your data" and actually allow an injection as a result. I insists on the different phrasing, says (with obvious grammar or styling check): --- This function must always be used to process every string (i.e. piece of data enclosed in the single quotes) added to the query. Note that this function doesn't make any data "safe" as it's just escaping special characters in the strings only and thus it is useless to protect other data types, such as numbers or identifiers. --- Same goes for the note, saying --- If this function is not used to escape data, the query is vulnerable to SQL Injection Attacks. --- "data" again! So, it is just false statement, as even if the function were used, there are circumstances under which your query remains vulnerable. Also, in account of the only purpose of this function, in should be explicitly noted that only prior call to mysql_set_charset() will make the mysql_real_escape_string different from mysql_escape_string() - i.e. make it " taking into account the current character set of the connection". Test script: --------------- $data = "1 union select password from users" $data = mysql_real_escape_string($data); $sql = "SELECT title FROM news WHERE id=$data"; Expected result: ---------------- The $data become "safe" and stopped injection. Actual result: -------------- The code above didn't make the data "safe" and didn't stop the injection. -- Edit bug report at https://bugs.php.net/bug.php?id=60398&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=60398&r=trysnapshot54 Try a snapshot (PHP 5.3): https://bugs.php.net/fix.php?id=60398&r=trysnapshot53 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=60398&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=60398&r=fixed Fixed in SVN and need be documented: https://bugs.php.net/fix.php?id=60398&r=needdocs Fixed in release: https://bugs.php.net/fix.php?id=60398&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=60398&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=60398&r=needscript Try newer version: https://bugs.php.net/fix.php?id=60398&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=60398&r=support Expected behavior: https://bugs.php.net/fix.php?id=60398&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=60398&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=60398&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=60398&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=60398&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=60398&r=dst IIS Stability: https://bugs.php.net/fix.php?id=60398&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=60398&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=60398&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=60398&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=60398&r=mysqlcfg

« previous php.doc.bugs (#7481) next »