Re: Re: PHP 4.3.3RC3 Released

From: Date: Thu, 14 Aug 2003 09:14:14 +0000
Subject: Re: Re: PHP 4.3.3RC3 Released
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-3908@lists.php.net to get a copy of this message
"Hartmut Holzgraefe" <hartmut@php.net> wrote in message news:3F3B4142.2060007@php.net... > Steven Brown wrote: > >>How is this a security hole? > > > > > > E.g., > > > > $id = "0; drop bar"; > > lamesql_query("select foo from bar where id = $id"); > > this is also possible with oracle, oci8 and other database extensions, > mysql ist the only one where i'm sure about that chaining is *not* > supported > > so the actual security hole is user code that puts *unverified* input > into SQL queries, so opening the door for SQL injection > > whether it makes sense to disable command chaining or at least make > it configurable with default 'off' in PHP database extensions is a > topic that may need further discussion (i know that Georg has similar > plans for mysqli in PHP 5), > but claiming that command chaining is a '*huge*' security hole per se > is not justified IMHO, this is more about how much protection against > "shoot yourself in the foot" incidents PHP should offer ... > the question is what is the common php programing habit. sinse there is no public recommendation on the manual (fix me here) or someware else, i assume thats the hebit is not always do verify the data and u can't blame the php users. btw, i doubt if u want to publish here the db sechema and url to system running oracle in ur ownership ... moshe.

« previous php.internals (#3908) next »