RE: [PHP] Security alert and question: semicolon taint

From: Date: Mon, 04 Sep 2000 04:50:12 +0000
Subject: RE: [PHP] Security alert and question: semicolon taint
Groups: php.general 
Request: Send a blank email to php-general+get-15049@lists.php.net to get a copy of this message
To Rasmus and the rest: Do you see a problem with just wrapping all the values in the query with quotes? That would seem like the simple way to do it. But I'll probably go back and error check the tainted values anyway. Speaking of which, does PHP have some sort of taint checking like Perl? At 15:41 9/4/2000 +1000, you wrote:
Now I'm worried. Magic slashes doesn't work for semicolons. So, what
should
I do? Is there some sort of magic slashes for semicolons? Should I just build checking functions for all input? Should I just wrap all values
like
$id in quotes?
If you know $id is supposed to be a number you need to force it to be such. ie. $id = (int)$id; Also, make sure the user/pass you're using for MySQL in PHP doesn't have any access to the server for Evil Things(tm). (Apologies to Rasmus, I accidentally emailled this to him personally - whoops) Jason -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net


« previous php.general (#15049) next »