Re: [RFC] is_literal()
| From: | Mike Schinkel | Date: | Mon, 23 Mar 2020 00:04:58 +0000 |
| Subject: | Re: [RFC] is_literal() | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-109218@lists.php.net to get a copy of this message | ||
> On Mar 22, 2020, at 7:14 PM, Craig Francis <craig@craigfrancis.co.uk> wrote:
>
> On Sun, 22 Mar 2020 at 19:11, Mike Schinkel <mike@newclarity.net> wrote:
>> [...] hash out potential solutions on the list rather than propose a specific one in
>> advance.
>
> As to your idea of a "safe" MySQL class, fortunately mysqli already stops multiple
> queries, so a SELECT cannot have an UPDATE/DELETE/TRUNCATE appended on to the end, but it can still
> do things like UNION another SELECT query, so the original query returns nothing, then the attackers
> query gets appended, potentially allowing them to extract everything from the database.
To follow up, a "safe" MySQL class *could* disallow UNION then, no?
In addition, it could possible have flags for every type of query and require you set on only the
aspects you need. Unions, Updates, Deletes, Truncates, Joins, Where, etc. much like firewalls start
will all ports closed.
Just spitballing, anyway.
-Mike