Re: [PATCH - PR] Disable ATTR_EMULATE_PREPARES by default for PDO_Mysql
| From: | Ulf Wendel | Date: | Sat, 16 Jun 2012 07:19:50 +0000 |
| Subject: | Re: [PATCH - PR] Disable ATTR_EMULATE_PREPARES by default for PDO_Mysql | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-60855@lists.php.net to get a copy of this message | ||
Am 15.06.2012 18:28, schrieb Christopher Jones:
On 06/15/2012 08:34 AM, Ulf Wendel wrote:Plain wrong. If client does not mess up on type and charsets there is no practical difference between the security of properly done client side escaping and server-side escaping. No matter if the subject of escaping is a fairy tale on goofy or any other string that happens to look like any other human invented format, e.g. SQL. UlfAs long as client-side escaping is done properly, there is no practical difference between the [client vs server -prepare] approaches.The big problem with this line of reasoning is that the client must know exactly the same dialect of SQL/XQUERY/whatever that the server does. Since we can't predict the future, and so a new DB might