Re: Secure eval();
| From: | 1LT John W. Holmes | Date: | Tue, 21 May 2002 14:39:16 +0000 |
| Subject: | Re: Secure eval(); | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-98603@lists.php.net to get a copy of this message | ||
Are you sure you have to run it through eval()? It sounds like you're
creating a query. Couldn't you just create the query dynamically, then put
it in a mysql_query() function? (or whatever DB you're using) Then, even if
they try some kung fu on you, it'll just result in a bad query, not some
rogue code being executed.
---John Holmes...
----- Original Message -----
From: "Chris Boget" <chris@wild.net>
To: "1LT John W. Holmes" <holmes072000@charter.net>; "PHP General"
<php-general@lists.php.net>
Sent: Tuesday, May 21, 2002 10:17 AM
Subject: Re: [PHP] Secure eval();
> > You'll have to come up with a regular expression to check for bad
> > characters. How complex are the equations? If they are like your
example,
> > you can just check that the equation doesn't have any letters and is
only
> > made up of [0-9+*-/()] characters.
>
> It's pretty complex. What I gave was a very simplistic example. The
numbers
> are actually going to be table.fieldnames and the values in those fields
are going
> to be referenced to get the actual number used in the equation. However,
once
> I interpolate the fieldnames to numbers I guess I could run the equation
against
> some sort of regex to make sure that it's valid.
> hmmm.... Might be easier than I thought.
>
> Thanks for the input!
>
> Chris
>