Re: ODBC_EXECUTE has a DANGEROUS 'feature'!!!

From: Date: Mon, 11 Feb 2002 14:48:37 +0000
Subject: Re: ODBC_EXECUTE has a DANGEROUS 'feature'!!!
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-84276@lists.php.net to get a copy of this message
> I'll echo Lars that you should always validate data, whether or not you > assume it to be safe. > That being said, if '/etc/passwd' is readable by your webserver you've got > bigger problems. > > Best regards, > Andrew Hill > Director of Technology Evangelism > http://www.openlinksw.com/virtuoso/whatis.htm > OpenLink Virtuoso Internet Data Integration Server Well Andrew... How do you check something that is safe? How do you check on bugs you don't know they exist? This bug(/'feature') isn't documented... How do you check on it? If you receive some text, eg. "Renze", how do you validate that? It's only normal characters. And at some moment it turns out te be that if you have an R at the start of your string PHP starts to do al kinds of crazy things. You can't know up front! [before you start wining about this... THIS IS AN EXAMPLE] Same thing with this problem. I can validate whatever I want, but quotes are simply allowed in the database. They're allowed in PHP. The bug/feature I came across isn't documented. NOT ANYWHERE!! So... Now you can tell me how to validate this......... I'll repeat myself again: If someone wants these kind of awful constructions, he/she should at least tell everyone that the construction is there! Documentation! -- * R&zE:

« previous php.general (#84276) next »