Re: Secure eval();

From: Date: Tue, 21 May 2002 14:39:16 +0000
Subject: Re: Secure eval();
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-98603@lists.php.net to get a copy of this message
Are you sure you have to run it through eval()? It sounds like you're creating a query. Couldn't you just create the query dynamically, then put it in a mysql_query() function? (or whatever DB you're using) Then, even if they try some kung fu on you, it'll just result in a bad query, not some rogue code being executed. ---John Holmes... ----- Original Message ----- From: "Chris Boget" <chris@wild.net> To: "1LT John W. Holmes" <holmes072000@charter.net>; "PHP General" <php-general@lists.php.net> Sent: Tuesday, May 21, 2002 10:17 AM Subject: Re: [PHP] Secure eval(); > > You'll have to come up with a regular expression to check for bad > > characters. How complex are the equations? If they are like your example, > > you can just check that the equation doesn't have any letters and is only > > made up of [0-9+*-/()] characters. > > It's pretty complex. What I gave was a very simplistic example. The numbers > are actually going to be table.fieldnames and the values in those fields are going > to be referenced to get the actual number used in the equation. However, once > I interpolate the fieldnames to numbers I guess I could run the equation against > some sort of regex to make sure that it's valid. > hmmm.... Might be easier than I thought. > > Thanks for the input! > > Chris >

« previous php.general (#98603) next »