note 63611 deleted from security.database.sql-injection by bjori
| From: | bjori@php.net | Date: | Sat, 25 Mar 2006 14:44:47 +0000 |
| Subject: | note 63611 deleted from security.database.sql-injection by bjori | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-106593@lists.php.net to get a copy of this message | ||
Note Submitter: fanfatal at fanfatal dot pl
Reason: bad code
----
Some of my usefull codes :)
<?php
/**
* Static class SQLi to prevent before SQL Injection
*
* @author FanFataL
*/
class SQLi {
/**
* Private method to choose which filter use to external data
*
* @param char $type
* @param string $value
* @access private
* @return mixed
* @author FanFataL
*/
function _prepare($type, $value = '') {
switch($type) {
case 't': return '
'.$value.''; // table name
case 's': return '\''.(get_magic_quotes_gpc() ? $value :
addslashes($value)).'\''; // string - for mysql e.g. use mysql_real_escape_string
case 'd': return (int)$value; // integer
case 'f': return (float)$value; // float value
}
return $value;
}
/**
* Build sql statement
*
* @param string $query
* @param [mixed $args [, mixed ...]]
* @access public
* @return string
* @author FanFataL
*/
function prepare($query) {
$args = func_get_args();
$i = 1;
return preg_replace('/\%([tsdf])/e', 'SQLi::_prepare(\'\\1\',
$args[$i++])', $query);
}
}
// example
$sql = SQLi::prepare('SELECT * FROM %t a INNER JOIN %t b ON b.id = a.id WHERE a.id=%d AND
a.topic LIKE %s',
'topic_table',
'user_table',
$_GET['id'],
'%'.$_POST['search_word'].'%'
);
// SELECT * FROM topic_table a INNER JOIN user_table b ON b.id = a.id
WHERE a.id=2 AND a.topic LIKE '%test\'test\"test%'
?>
Greetings ;)
...