RE: [PHP] Security alert and question: semicolon taint

From: Date: Mon, 04 Sep 2000 05:41:50 +0000
Subject: RE: [PHP] Security alert and question: semicolon taint
Groups: php.general 
Request: Send a blank email to php-general+get-15047@lists.php.net to get a copy of this message
> > Now I'm worried. Magic slashes doesn't work for semicolons. So, what should > > I do? Is there some sort of magic slashes for semicolons? Should I just > > build checking functions for all input? Should I just wrap all values like > > $id in quotes? > > If you know $id is supposed to be a number you need to force it to be > such. ie. > > $id = (int)$id; Also, make sure the user/pass you're using for MySQL in PHP doesn't have any access to the server for Evil Things(tm). (Apologies to Rasmus, I accidentally emailled this to him personally - whoops) Jason

« previous php.general (#15047) next »