Re: ODBC_EXECUTE has a DANGEROUS 'feature'!!!
| From: | * R&zE: | Date: | Mon, 11 Feb 2002 14:48:37 +0000 |
| Subject: | Re: ODBC_EXECUTE has a DANGEROUS 'feature'!!! | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-84276@lists.php.net to get a copy of this message | ||
> I'll echo Lars that you should always validate data, whether or not you
> assume it to be safe.
> That being said, if '/etc/passwd' is readable by your webserver you've got
> bigger problems.
>
> Best regards,
> Andrew Hill
> Director of Technology Evangelism
> http://www.openlinksw.com/virtuoso/whatis.htm
> OpenLink Virtuoso Internet Data Integration Server
Well Andrew...
How do you check something that is safe?
How do you check on bugs you don't know they exist? This
bug(/'feature') isn't documented... How do you check on it?
If you receive some text, eg. "Renze", how do you validate that?
It's only normal characters. And at some moment it turns out te be
that if you have an R at the start of your string PHP starts to do
al kinds of crazy things. You can't know up front!
[before you start wining about this... THIS IS AN EXAMPLE]
Same thing with this problem. I can validate whatever I want, but
quotes are simply allowed in the database. They're allowed in PHP.
The bug/feature I came across isn't documented. NOT ANYWHERE!!
So... Now you can tell me how to validate this.........
I'll repeat myself again:
If someone wants these kind of awful constructions, he/she should at
least tell everyone that the construction is there! Documentation!
--
* R&zE: