Re: Security alert and question: semicolon taint
| From: | Simon Edwards | Date: | Mon, 04 Sep 2000 04:09:16 +0000 |
| Subject: | Re: Security alert and question: semicolon taint | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15042@lists.php.net to get a copy of this message | ||
Kent Wang wrote:
> Stop me if I'm wrong, but when I perform a standard SQL query like this:
> [snip! magic slashes and sql doesn't work all the time]
> Fortunately, magic slashes solves this problem. Note to newbies: this is a
> great reason to use magic slashes.
Personally I think that magic slashes is at least a pain the ass, and at
the most a dangerous false sense of security. The problem is that
different things require different encodings (not to mention the fact
that all your string handling goes to hell).
> Now I'm worried. Magic slashes doesn't work for semicolons. So, what should
> I do? Is there some sort of magic slashes for semicolons? Should I just
> build checking functions for all input? Should I just wrap all values like
> $id in quotes?
What you are supposed to do is to 'clean' all values that come in from
the outside world. All form values (GET or POST method) need to be
cleaned. If $id is an integer then you have to make sure that the user
passed you an integer, otherwise you can't trust that value. Also if you
are building an SQL query make sure that all the strings are encoded
properly and quoted.
Also I found that back in the PHP 2 days, managing string handling with
addslashes() and stripslashes() quickly became a nightmare. I'm just
glad that I can now turn it off and do things correctly: check variables
when they come in, and apply the correct encoding when I output it in a
query, url or just plain HTML text.
--
Simon Edwards
Animated Design, Melbourne
http://www.animated.net.au/ Ph: (03) 98850990