note 37572 added to function.setcookie

From: Date: Thu, 20 Nov 2003 00:08:27 +0000
Subject: note 37572 added to function.setcookie
Groups: php.notes 
Request: Send a blank email to php-notes+get-60647@lists.php.net to get a copy of this message
You may want to keep this in mind when setting cookies then comparing them agaist a database When you extract a cookie and compare it straight agaist the db ("SELECT UserID from Users WHERE user=$_COOKIE[user] AND pass=$_COOKIE[pass]") you are making you script expliotable by an older SQL exploit. If the user changes there cookies and sets all feilds to ('='' or ''') thn the SQL statement would be ("SELECT UserID from Users WHERE user='='' or ''' AND pass='='' or '''") and nothing will always equal nothing. All you need to do to stop this is either addslashes() after you extract the cookie or md5 the contents of the cookie then md5 the contents of the table in your query ("SELECT UserID from Users WHERE md5(user)=$_COOKIE[user] AND md5(pass)=$_COOKIE[pass]"). or heres some code i use <? //Setting the cookie //just put all you contents in the array //if you need to be able to read it dont md5 it but if its just for comparing in the database md5 it $thiscookie[0] = md5($username); $thiscookie[1] = md5($password); $s_thiscookie=implode(md5("^*^"),$thiscookie); //can replace ^*^ with anything just make sure you remember it for latter setcookie ('UserData', $s_thiscookie,time()+60*60*24*30, '/'); //cookie is set for 30days //to check users cookie is valid $UserData = $_COOKIE['UserData']; $UserData=explode(md5("^*^"),$UserData); //Puts the cookie Data back into an array $result = mysql_query("SELECT UserID FROM Users WHERE md5(user)= '" . $UserData[0] . "' AND md5(pass)= '" . $UserData[1] . "'"); //*Note: If the password is already md5ed inside the database dont md5 it in the query. ?> The cookies value will be something like "c4ca4238a0b923820dcc509a6f75849b7d010443693eec253a121e2aa2ba177cb6" even tho using that same script you will not be able to read the above string as it was imploded using || not ^*^ chnage ^*^ to || and you can divide it up but then you still have to know what order the cookies are in and so on. I find this the best way to secure your cookies, and its not exploitable with the sql exploit because everything is md5ed so it would no longer go to the DataBase as ('='' or ''') will be (b6b94e437c8adf9a7ab1a450e71a2124). For a faster easyer way block sql explioting use addslashes,like "SELECT UserID FROM tbldomains WHERE md5(Domain)= '" . addslashes($UserData[0]) . "' AND md5(Password)= '" . addslashes($UserData[1]) . "'" ---- Manual Page -- http://www.php.net/manual/en/function.setcookie.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+37572 Delete -- http://master.php.net/manage/user-notes.php?action=delete+37572&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+37572&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#60647) next »