note 37572 deleted from function.setcookie by pollita
| From: | pollita@php.net | Date: | Thu, 20 Nov 2003 00:41:44 +0000 |
| Subject: | note 37572 deleted from function.setcookie by pollita | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-60653@lists.php.net to get a copy of this message | ||
Note Submitter: rodus AT netspace dot net dot au
----
You may want to keep this in mind when setting cookies then comparing them agaist a database
When you extract a cookie and compare it straight agaist the db ("SELECT UserID from
Users WHERE user=$_COOKIE[user] AND pass=$_COOKIE[pass]") you are making you
script expliotable by an older SQL exploit. If the user changes there cookies and sets all feilds to
('='' or ''') thn the SQL statement would be ("SELECT UserID from
Users WHERE user='='' or ''' AND pass='=''
or '''") and nothing will always equal nothing.
All you need to do to stop this is either addslashes() after you extract the cookie or md5 the
contents of the cookie then md5 the contents of the table in your query ("SELECT UserID from
Users WHERE md5(user)=$_COOKIE[user] AND md5(pass)=$_COOKIE[pass]").
or heres some code i use
<?
//Setting the cookie
//just put all you contents in the array
//if you need to be able to read it dont md5 it but if its just for comparing in the database md5 it
$thiscookie[0] = md5($username);
$thiscookie[1] = md5($password);
$s_thiscookie=implode(md5("^*^"),$thiscookie); //can replace ^*^ with anything just make
sure you remember it for latter
setcookie ('UserData', $s_thiscookie,time()+60*60*24*30, '/'); //cookie is set
for 30days
//to check users cookie is valid
$UserData = $_COOKIE['UserData'];
$UserData=explode(md5("^*^"),$UserData); //Puts the cookie Data back into an array
$result = mysql_query("SELECT UserID FROM Users WHERE md5(user)= '" .
$UserData[0] . "' AND md5(pass)= '" . $UserData[1] . "'");
//*Note: If the password is already md5ed inside the database dont md5 it in the query.
?>
The cookies value will be something like
"c4ca4238a0b923820dcc509a6f75849b7d010443693eec253a121e2aa2ba177cb6" even tho using that
same script you will not be able to read the above string as it was imploded using || not ^*^ chnage
^*^ to || and you can divide it up but then you still have to know what order the cookies are in and
so on.
I find this the best way to secure your cookies, and its not exploitable with the sql exploit
because everything is md5ed so it would no longer go to the DataBase as ('='' or
''') will be (b6b94e437c8adf9a7ab1a450e71a2124).
For a faster easyer way block sql explioting use addslashes,like "SELECT UserID FROM
tbldomains WHERE md5(Domain)= '" . addslashes($UserData[0]) . "'
AND md5(Password)= '" . addslashes($UserData[1]) . "'"