Re: [RFC] Block requests to builtin SQL functions where PHP can prove the call is vulnerable to a potential SQL-injection attack
| From: | Yasuo Ohgaki | Date: | Fri, 07 Aug 2015 01:36:45 +0000 |
| Subject: | Re: [RFC] Block requests to builtin SQL functions where PHP can prove the call is vulnerable to a potential SQL-injection attack | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-87674@lists.php.net to get a copy of this message | ||
On Fri, Aug 7, 2015 at 10:29 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> Even if there is identifier placeholder, SQL keyword remains.
> So to be perfect, you'll need another place holder for SQL keywords.
> There is no escaping for SQL keywords and it has to be validation.
> e.g. ORDER BY {$_GET['order']}
>
Oops the last line should be
e.g. ORDER BY col {$_GET['order']}
BTW, instead of improving PHP, users are better to request "identifier
escape API"
to DB developers like PQescapeIdentifier() in PostgreSQL's client library.
IMO.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net