Re: Serialised Data & DBs
| From: | Danny Shepherd | Date: | Tue, 30 Jul 2002 21:23:50 +0000 |
| Subject: | Re: Serialised Data & DBs | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-110421@lists.php.net to get a copy of this message | ||
----- Original Message -----
From: "1LT John W. Holmes" <holmes072000@charter.net>
To: "Danny Shepherd" <danny@kyboshed.com>; "PHP-General"
<php-general@lists.php.net>
Sent: Tuesday, July 30, 2002 8:18 PM
Subject: Re: [PHP] Serialised Data & DBs
> Yes, it'd be really smart to. If any of the data in the serialized string
> has a ' or " in it, it could break your query. Or the user being able to
> enter a ' or " into the data could open you to SQL attacks.
>
> You want to do addslashes() on the result of serialize(), not the content
> going into it, too. PHP will introduct double quotes around any strings
that
> are serialized. These should be escaped or they could end up breaking your
> query.
Yeah, the contents are already stripslashed.
> Note that you don't have to do stripslashes() on the serialized string
when
> you pull it out.
Cool, didn't realise that - would've been hard to track down later too!
Thanks,
Danny.