Re: Security alert and question: semicolon taint
| From: | Rasmus Lerdorf | Date: | Mon, 04 Sep 2000 04:22:54 +0000 |
| Subject: | Re: Security alert and question: semicolon taint | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15044@lists.php.net to get a copy of this message | ||
> mysql_query("INSERT INTO tasks SET id = $id");
>
> Note that I don't have quotes around $id this time, because $id is supposed
> to be a number. However, what if some malicious user set this as $id:
>
> 0; DROP TABLE tasks
>
> Now I'm worried. Magic slashes doesn't work for semicolons. So, what should
> I do? Is there some sort of magic slashes for semicolons? Should I just
> build checking functions for all input? Should I just wrap all values like
> $id in quotes?
If you know $id is supposed to be a number you need to force it to be
such. ie.
$id = (int)$id;
-Rasmus