Doc #60398 [NEW]: mysql_real_escape_string description is wrong and decieving
| From: | col dot shrapnel at gmail dot com | Date: | Sun, 27 Nov 2011 10:26:39 +0000 |
| Subject: | Doc #60398 [NEW]: mysql_real_escape_string description is wrong and decieving | ||
| Groups: | php.doc.bugs | ||
| Request: | Send a blank email to doc-bugs+get-7481@lists.php.net to get a copy of this message | ||
From:
Operating system: irrelevant
PHP version: Irrelevant
Package: Documentation problem
Bug Type: Documentation Problem
Bug description:mysql_real_escape_string description is wrong and decieving
Description:
------------
---
From manual page:
http://www.php.net/function.mysql-real-escape-string#refsect1-
function.mysql-real-escape-string-description
---
I am writing in account of the mysql_real_escape_string() description,
which
current phrasing is erroneous and decieving, leading thousands of PHP
programmers to confusion and make them writing the code that actually
_allows_
injection.
It says at the moment
---
This function must always (with few exceptions) be used to make data safe
before
sending a query to MySQL.
---
Which is obviously wrong, as the function doesn't make data whatever
"safe".
And "few exceptions" statement is not an excuse as it explains nothing.
Based on this very description, many people having an idea of injection
protection limited to just "escape all your data" and actually allow an
injection as a result.
I insists on the different phrasing, says (with obvious grammar or styling
check):
---
This function must always be used to process every string (i.e. piece of
data
enclosed in the single quotes) added to the query.
Note that this function doesn't make any data "safe" as it's just escaping
special characters in the strings only and thus it is useless to protect
other
data types, such as numbers or identifiers.
---
Same goes for the note, saying
---
If this function is not used to escape data, the query is vulnerable to SQL
Injection Attacks.
---
"data" again!
So, it is just false statement, as even if the function were used, there
are
circumstances under which your query remains vulnerable.
Also, in account of the only purpose of this function, in should be
explicitly
noted that only prior call to mysql_set_charset() will make the
mysql_real_escape_string different from mysql_escape_string() - i.e. make
it "
taking into account the current character set of the connection".
Test script:
---------------
$data = "1 union select password from users"
$data = mysql_real_escape_string($data);
$sql = "SELECT title FROM news WHERE id=$data";
Expected result:
----------------
The $data become "safe" and stopped injection.
Actual result:
--------------
The code above didn't make the data "safe" and didn't stop the injection.
--
Edit bug report at https://bugs.php.net/bug.php?id=60398&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=60398&r=trysnapshot54
Try a snapshot (PHP 5.3): https://bugs.php.net/fix.php?id=60398&r=trysnapshot53
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=60398&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=60398&r=fixed
Fixed in SVN and need be documented: https://bugs.php.net/fix.php?id=60398&r=needdocs
Fixed in release: https://bugs.php.net/fix.php?id=60398&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=60398&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=60398&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=60398&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=60398&r=support
Expected behavior: https://bugs.php.net/fix.php?id=60398&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=60398&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=60398&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=60398&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=60398&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=60398&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=60398&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=60398&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=60398&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=60398&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=60398&r=mysqlcfg