Re: Security alert and question: semicolon taint
| From: | Kent Wang | Date: | Mon, 04 Sep 2000 14:47:10 +0000 |
| Subject: | Re: Security alert and question: semicolon taint | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15138@lists.php.net to get a copy of this message | ||
Well, I got my panties in a wad over nothing. Turns out msql_query doesn't allow the use of semicolons. You should still check your input though.
At 22:20 9/3/2000 -0500, Kent Wang wrote:
Stop me if I'm wrong, but when I perform a standard SQL query like this: mysql_query("INSERT INTO tasks SET name = '$name'"); Where $name and $id are form values that have not been checked. I know somebody in theory could set $name to: ';DROP TABLE tasks;SELECT 'blah Therefore, if this were executed, the following SQL query would actually be sent: INSERT INTO tasks SET name = '';DROP TABLE tasks;SELECT 'blah' So, it'll send some insert some phony value, DROP my table, then select some more phony data. Fortunately, magic slashes solves this problem. Note to newbies: this is a great reason to use magic slashes. However, I'm still worried. What if my code was: mysql_query("INSERT INTO tasks SET id = $id"); Note that I don't have quotes around $id this time, because $id is supposed to be a number. However, what if some malicious user set this as $id: 0; DROP TABLE tasks Now I'm worried. Magic slashes doesn't work for semicolons. So, what should I do? Is there some sort of magic slashes for semicolons? Should I just build checking functions for all input? Should I just wrap all values like $id in quotes? Kent Wang -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net