note 37898 added to function.mysql-query

From: Date: Mon, 01 Dec 2003 17:55:22 +0000
Subject: note 37898 added to function.mysql-query
Groups: php.notes 
Request: Send a blank email to php-notes+get-61226@lists.php.net to get a copy of this message
Why addslashes() or mysql_real_escape_string() should be used around mysql variables... Compare the following lines... <?PHP mysql_query ('delete from TABLE where ID="' . $_GET['ID'] . '"'); mysql_query ('delete from TABLE where ID="' . addslashes ($_GET['ID']) . '"'); ?> And now the user / hacker sends... 134"; drop database database name; This could potentially delete the record which has an ID of 134, then delete the whole database!!! The addslashes (second example) would sort out this problem by setting the user input to... 134\"; drop database database name; So the double quote is ignored, so it tries to delete the record with the specified ID (which because of all the text won't exist) But with all this said you should STILL be doing validation on your submitted values. Here are some things I check... <?PHP //-------------------------------- // Validation $OUTPUT = ''; if (!is_int ($_GET['AGE'])) { $OUTPUT .= '<li>AGE has to be an Integer</li>'; } if ($_GET['NAME'] != '') { $OUTPUT .= '<li>NAME has to have a value</li>'; } if (strlen($_GET['NAME']) > 50) { $OUTPUT .= '<li>NAME cannot be longer than 50 characters</li>'; } if ($_GET['GENDER'] != 'female' && $_GET['GENDER'] != 'male') { $OUTPUT .= '<li>GENDER must be set to male or female</li>'; } //-------------------------------- // If $OUTPUT doesn't have a // value then insert into the // database (cut down version)... if ($OUTPUT == '') { mysql_query ('insert into TABLE (NAME) VALUES ("' . addslashes ($_GET['NAME']) . '")'); if (mysql_affected_rows() == 1) { $OUTPUT .= '<li>Record Entered!</li>'; } else { $OUTPUT .= '<li>Database Error!</li>'; } } //-------------------------------- // Now Print out $OUTPUT echo ' <ul> ' . $OUTPUT . ' </ul>'; ?> You may think this is overkill, and you're probably right, but how many people do you know who go around submitting incorrect data? - I know I do when filling out a form to get access to some trial software (I don't want those companies knowing where I live etc). But on the other side, there are hackers out there trying over and over again to find a way into your website - the more validation you put in, the harder is will be for them to gain access! As "allen a brooker gb net" said, "don't trust ANY data that is sent to your script" NOTES: In several installations of PHP you can't submit more than one SQL query at a time (but it does help if you're aware of the problem). Also, I use capital variables because I like them, they stand out (my personal preference), the same is true with the layout of the IF statements. ---- Manual Page -- http://www.php.net/manual/en/function.mysql-query.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+37898 Delete -- http://master.php.net/manage/user-notes.php?action=delete+37898&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+37898&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#61226) next »