RE: [PHP] Security alert and question: semicolon taint
| From: | Kent Wang | Date: | Mon, 04 Sep 2000 04:50:12 +0000 |
| Subject: | RE: [PHP] Security alert and question: semicolon taint | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-15049@lists.php.net to get a copy of this message | ||
To Rasmus and the rest:
Do you see a problem with just wrapping all the values in the query with quotes? That would seem like the simple way to do it. But I'll probably go back and error check the tainted values anyway. Speaking of which, does PHP have some sort of taint checking like Perl?
At 15:41 9/4/2000 +1000, you wrote:
Now I'm worried. Magic slashes doesn't work for semicolons. So, whatshouldI do? Is there some sort of magic slashes for semicolons? Should I just build checking functions for all input? Should I just wrap all valueslike$id in quotes?If you know $id is supposed to be a number you need to force it to be such. ie. $id = (int)$id; Also, make sure the user/pass you're using for MySQL in PHP doesn't have any access to the server for Evil Things(tm). (Apologies to Rasmus, I accidentally emailled this to him personally - whoops) Jason -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net