RE: [PHP] Security alert and question: semicolon taint
| From: | Jason Murray | Date: | Mon, 04 Sep 2000 05:41:50 +0000 |
| Subject: | RE: [PHP] Security alert and question: semicolon taint | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-15047@lists.php.net to get a copy of this message | ||
> > Now I'm worried. Magic slashes doesn't work for semicolons. So, what
should
> > I do? Is there some sort of magic slashes for semicolons? Should I just
> > build checking functions for all input? Should I just wrap all values
like
> > $id in quotes?
>
> If you know $id is supposed to be a number you need to force it to be
> such. ie.
>
> $id = (int)$id;
Also, make sure the user/pass you're using for MySQL in PHP doesn't have any
access to the server for Evil Things(tm).
(Apologies to Rasmus, I accidentally emailled this to him personally -
whoops)
Jason