Re: Re: PHP 4.3.3RC3 Released
| From: | moshe doron | Date: | Thu, 14 Aug 2003 08:55:37 +0000 |
| Subject: | Re: Re: PHP 4.3.3RC3 Released | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-3904@lists.php.net to get a copy of this message | ||
"Steven Brown" <swbrown@ucsd.edu> wrote in message
news:000001c36237$f92a5410$1b0fa518@swbrown...
>
>
> > -----Original Message-----
> > From: Derick Rethans [mailto:derick@php.net]
> > Sent: Thursday, August 14, 2003 12:33 AM
> > To: moshe doron
> > Cc: internals@lists.php.net
> > Subject: Re: [PHP-DEV] Re: PHP 4.3.3RC3 Released
> >
> >
> > On Thu, 14 Aug 2003, moshe doron wrote:
> >
> > > What about hacking somehow the sqlite library to disallow chained
> > > queries (or at least do it optionally)?
> > >
> > > This behavior is *huge* security hole, allow to the cracker drop ur
> > > database using simple select where query.
> >
> > How is this a security hole?
>
> E.g.,
>
> $id = "0; drop bar";
> lamesql_query("select foo from bar where id = $id");
>
that's the mysql way....
with sybase style (used by sqlite), the is no need to separator, makes the
detection even harded.
(i used using pear sql_parser before executing the query but u can also turn
on sybase magic mode (worst choice ! it's buggy) and *always* encapsulate
the vars cames from the user with " ' ")
moshe.