RE: [PHP] extract($_POST)

From: Date: Fri, 25 Oct 2002 22:22:50 +0000
Subject: RE: [PHP] extract($_POST)
Groups: php.general 
Request: Send a blank email to php-general+get-121491@lists.php.net to get a copy of this message
You can still create a sub-query to do the damage. Jason -----Original Message----- From: John W. Holmes [mailto:holmes072000@charter.net] Sent: Friday, October 25, 2002 4:01 PM To: 'Rick Emery'; 'Chris Boget'; php-general@lists.php.net; 'Monty' Subject: RE: [PHP] extract($_POST) No, this can't happen. There can only be one SQL query per mysql_query(). Google for SQL injection or something and I'm sure you'll find examples. ---John Holmes... > -----Original Message----- > From: Rick Emery [mailto:remery@emeryloftus.com] > Sent: Friday, October 25, 2002 4:59 PM > To: Chris Boget; php-general@lists.php.net; Monty > Subject: Re: [PHP] extract($_POST) > > Lets say you have a statement like: > $query = "SELECT * FROM mytable WHERE firstname=$firstname"; > > And if $firstname is set to: > "xyz"; DELETE FROM mytable > > Then this is executed as: SELECT* FROM mytable WHERE > firstname="xyz";DELETE FROM mytable > > This can wipe out your table...a bad thing... > > ----- Original Message ----- > From: "Chris Boget" <chris@wild.net> > To: "Rick Emery" <remery@emeryloftus.com>; <php-general@lists.php.net>; > "Monty" > <monty3@hotmail.com> > Sent: Friday, October 25, 2002 3:41 PM > Subject: Re: [PHP] extract($_POST) > > > This thread has been great! I've learned so much useful stuff. > > > For instance, if you expect a variable called $firstname to contain > > a name to be stored in a SQL database, be certain it does not contain > > SQL commands which can damage your database. > > This is another thing I'd be interested in hearing more about. If all you > are doing is storing and retrieving data, what commands could possibly > be defined that could damage your database? > > $firstName = "Chris"; > mysql_query( "INSERT INTO names ( first_name ) VALUES ( \"$firstName\" )" > ); > $result = mysql_query( "SELECT first_name FROM names" ); > while( $dataArray = mysql_fetch_assoc( $result )) { > echo $dataArray["first_name"] > > } > > If $firstName was set by a form submission, what malicious SQL code could > damage your database? All you are doing is storing, retreiving and > displaying > data... > > Chris > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php > > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php

« previous php.general (#121491) next »