Security alert and question: semicolon taint
| From: | Kent Wang | Date: | Mon, 04 Sep 2000 03:20:06 +0000 |
| Subject: | Security alert and question: semicolon taint | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-15041@lists.php.net to get a copy of this message | ||
Stop me if I'm wrong, but when I perform a standard SQL query like this:
mysql_query("INSERT INTO tasks SET name = '$name'");
Where $name and $id are form values that have not been checked. I know somebody in theory could set $name to:
';DROP TABLE tasks;SELECT 'blah
Therefore, if this were executed, the following SQL query would actually be sent:
INSERT INTO tasks SET name = '';DROP TABLE tasks;SELECT 'blah'
So, it'll send some insert some phony value, DROP my table, then select some more phony data.
Fortunately, magic slashes solves this problem. Note to newbies: this is a great reason to use magic slashes.
However, I'm still worried. What if my code was:
mysql_query("INSERT INTO tasks SET id = $id");
Note that I don't have quotes around $id this time, because $id is supposed to be a number. However, what if some malicious user set this as $id:
0; DROP TABLE tasks
Now I'm worried. Magic slashes doesn't work for semicolons. So, what should I do? Is there some sort of magic slashes for semicolons? Should I just build checking functions for all input? Should I just wrap all values like $id in quotes?
Kent Wang