note 63611 deleted from security.database.sql-injection by bjori

From: Date: Sat, 25 Mar 2006 14:44:47 +0000
Subject: note 63611 deleted from security.database.sql-injection by bjori
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-106593@lists.php.net to get a copy of this message
Note Submitter: fanfatal at fanfatal dot pl Reason: bad code ---- Some of my usefull codes :) <?php /** * Static class SQLi to prevent before SQL Injection * * @author FanFataL */ class SQLi { /** * Private method to choose which filter use to external data * * @param char $type * @param string $value * @access private * @return mixed * @author FanFataL */ function _prepare($type, $value = '') { switch($type) { case 't': return ''.$value.''; // table name case 's': return '\''.(get_magic_quotes_gpc() ? $value : addslashes($value)).'\''; // string - for mysql e.g. use mysql_real_escape_string case 'd': return (int)$value; // integer case 'f': return (float)$value; // float value } return $value; } /** * Build sql statement * * @param string $query * @param [mixed $args [, mixed ...]] * @access public * @return string * @author FanFataL */ function prepare($query) { $args = func_get_args(); $i = 1; return preg_replace('/\%([tsdf])/e', 'SQLi::_prepare(\'\\1\', $args[$i++])', $query); } } // example $sql = SQLi::prepare('SELECT * FROM %t a INNER JOIN %t b ON b.id = a.id WHERE a.id=%d AND a.topic LIKE %s', 'topic_table', 'user_table', $_GET['id'], '%'.$_POST['search_word'].'%' ); // SELECT * FROM topic_table a INNER JOIN user_table b ON b.id = a.id WHERE a.id=2 AND a.topic LIKE '%test\'test\"test%' ?> Greetings ;) ...

« previous php.notes (#106593) next »