note 39291 added to function.mysql-escape-string
| From: | administrator at manga-torii dot com | Date: | Fri, 23 Jan 2004 10:36:12 +0000 |
| Subject: | note 39291 added to function.mysql-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-64059@lists.php.net to get a copy of this message | ||
I can't understand why all mysql functions use the \ character to escape special character in
queries.
THIS IS NOT SQL STANDARD COMPLIANT!
To escape the ' character, the real way is to double the character, so it becomes ''
(two '). Same thing for all other characters such as % becomes %%.
By the current way, when we use Oracle or MSSQL Server by exemple, the result of this function (also
MagicQuote) is an error while doing the query, or worste, the query is not protected.
select * from users where name = '$login' and password='$password'
With $login = "admin" and $password = "dummy' or 1 = 1 --" the query
becomes:
select * from users where name = 'admin' and password='dummy\' or 1 = 1 --'
And then Oracle or MSSQL Server will run the query without understanding the \' as an escaped
' character, so the query is not protected at all!
As a result, the user can logon as "admin" even if he don't know the real password!
----
Manual Page -- http://www.php.net/manual/en/function.mysql-escape-string.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+39291
Delete -- http://master.php.net/manage/user-notes.php?action=delete+39291&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+39291&report=yes
Search -- http://master.php.net/manage/user-notes.php