Re: Re: PHP 4.3.3RC3 Released

From: Date: Thu, 14 Aug 2003 08:55:37 +0000
Subject: Re: Re: PHP 4.3.3RC3 Released
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-3904@lists.php.net to get a copy of this message
"Steven Brown" <swbrown@ucsd.edu> wrote in message news:000001c36237$f92a5410$1b0fa518@swbrown... > > > > -----Original Message----- > > From: Derick Rethans [mailto:derick@php.net] > > Sent: Thursday, August 14, 2003 12:33 AM > > To: moshe doron > > Cc: internals@lists.php.net > > Subject: Re: [PHP-DEV] Re: PHP 4.3.3RC3 Released > > > > > > On Thu, 14 Aug 2003, moshe doron wrote: > > > > > What about hacking somehow the sqlite library to disallow chained > > > queries (or at least do it optionally)? > > > > > > This behavior is *huge* security hole, allow to the cracker drop ur > > > database using simple select where query. > > > > How is this a security hole? > > E.g., > > $id = "0; drop bar"; > lamesql_query("select foo from bar where id = $id"); > that's the mysql way.... with sybase style (used by sqlite), the is no need to separator, makes the detection even harded. (i used using pear sql_parser before executing the query but u can also turn on sybase magic mode (worst choice ! it's buggy) and *always* encapsulate the vars cames from the user with " ' ") moshe.

« previous php.internals (#3904) next »