Re: Security alert and question: semicolon taint

From: Date: Mon, 04 Sep 2000 04:09:16 +0000
Subject: Re: Security alert and question: semicolon taint
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-15042@lists.php.net to get a copy of this message
Kent Wang wrote: > Stop me if I'm wrong, but when I perform a standard SQL query like this: > [snip! magic slashes and sql doesn't work all the time] > Fortunately, magic slashes solves this problem. Note to newbies: this is a > great reason to use magic slashes. Personally I think that magic slashes is at least a pain the ass, and at the most a dangerous false sense of security. The problem is that different things require different encodings (not to mention the fact that all your string handling goes to hell). > Now I'm worried. Magic slashes doesn't work for semicolons. So, what should > I do? Is there some sort of magic slashes for semicolons? Should I just > build checking functions for all input? Should I just wrap all values like > $id in quotes? What you are supposed to do is to 'clean' all values that come in from the outside world. All form values (GET or POST method) need to be cleaned. If $id is an integer then you have to make sure that the user passed you an integer, otherwise you can't trust that value. Also if you are building an SQL query make sure that all the strings are encoded properly and quoted. Also I found that back in the PHP 2 days, managing string handling with addslashes() and stripslashes() quickly became a nightmare. I'm just glad that I can now turn it off and do things correctly: check variables when they come in, and apply the correct encoding when I output it in a query, url or just plain HTML text. -- Simon Edwards Animated Design, Melbourne http://www.animated.net.au/ Ph: (03) 98850990

« previous php.general (#15042) next »