Security alert and question: semicolon taint

From: Date: Mon, 04 Sep 2000 03:20:06 +0000
Subject: Security alert and question: semicolon taint
Groups: php.general 
Request: Send a blank email to php-general+get-15041@lists.php.net to get a copy of this message
Stop me if I'm wrong, but when I perform a standard SQL query like this: mysql_query("INSERT INTO tasks SET name = '$name'"); Where $name and $id are form values that have not been checked. I know somebody in theory could set $name to: ';DROP TABLE tasks;SELECT 'blah Therefore, if this were executed, the following SQL query would actually be sent: INSERT INTO tasks SET name = '';DROP TABLE tasks;SELECT 'blah' So, it'll send some insert some phony value, DROP my table, then select some more phony data. Fortunately, magic slashes solves this problem. Note to newbies: this is a great reason to use magic slashes. However, I'm still worried. What if my code was: mysql_query("INSERT INTO tasks SET id = $id"); Note that I don't have quotes around $id this time, because $id is supposed to be a number. However, what if some malicious user set this as $id: 0; DROP TABLE tasks Now I'm worried. Magic slashes doesn't work for semicolons. So, what should I do? Is there some sort of magic slashes for semicolons? Should I just build checking functions for all input? Should I just wrap all values like $id in quotes? Kent Wang

« previous php.general (#15041) next »