note 37898 added to function.mysql-query
| From: | krang at krang dot org dot uk | Date: | Mon, 01 Dec 2003 17:55:22 +0000 |
| Subject: | note 37898 added to function.mysql-query | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-61226@lists.php.net to get a copy of this message | ||
Why addslashes() or mysql_real_escape_string() should be used around mysql variables...
Compare the following lines...
<?PHP
mysql_query ('delete from TABLE where ID="' . $_GET['ID'] .
'"');
mysql_query ('delete from TABLE where ID="' . addslashes ($_GET['ID']) .
'"');
?>
And now the user / hacker sends...
134"; drop database
database name;
This could potentially delete the record which has an ID of 134, then delete the whole database!!!
The addslashes (second example) would sort out this problem by setting the user input to...
134\"; drop database database name;
So the double quote is ignored, so it tries to delete the record with the specified ID (which
because of all the text won't exist)
But with all this said you should STILL be doing validation on your submitted values. Here are some
things I check...
<?PHP
//--------------------------------
// Validation
$OUTPUT = '';
if (!is_int ($_GET['AGE'])) {
$OUTPUT .= '<li>AGE has to be an Integer</li>';
}
if ($_GET['NAME'] != '') {
$OUTPUT .= '<li>NAME has to have a value</li>';
}
if (strlen($_GET['NAME']) > 50) {
$OUTPUT .= '<li>NAME cannot be longer than 50 characters</li>';
}
if ($_GET['GENDER'] != 'female' && $_GET['GENDER'] !=
'male') {
$OUTPUT .= '<li>GENDER must be set to male or female</li>';
}
//--------------------------------
// If $OUTPUT doesn't have a
// value then insert into the
// database (cut down version)...
if ($OUTPUT == '') {
mysql_query ('insert into TABLE (NAME) VALUES ("' . addslashes
($_GET['NAME']) . '")');
if (mysql_affected_rows() == 1) {
$OUTPUT .= '<li>Record Entered!</li>';
} else {
$OUTPUT .= '<li>Database Error!</li>';
}
}
//--------------------------------
// Now Print out $OUTPUT
echo '
<ul>
' . $OUTPUT . '
</ul>';
?>
You may think this is overkill, and you're probably right, but how many people do you know who
go around submitting incorrect data? - I know I do when filling out a form to get access to some
trial software (I don't want those companies knowing where I live etc).
But on the other side, there are hackers out there trying over and over again to find a way into
your website - the more validation you put in, the harder is will be for them to gain access!
As "allen a brooker gb net" said, "don't trust ANY data that is sent to your
script"
NOTES: In several installations of PHP you can't submit more than one SQL query at a time (but
it does help if you're aware of the problem). Also, I use capital variables because I like
them, they stand out (my personal preference), the same is true with the layout of the IF
statements.
----
Manual Page -- http://www.php.net/manual/en/function.mysql-query.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+37898
Delete -- http://master.php.net/manage/user-notes.php?action=delete+37898&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+37898&report=yes
Search -- http://master.php.net/manage/user-notes.php