note 39291 deleted from function.mysql-escape-string by nlopess

From: Date: Fri, 23 Jan 2004 19:13:32 +0000
Subject: note 39291 deleted from function.mysql-escape-string by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-64078@lists.php.net to get a copy of this message
Note Submitter: administrator@manga-torii.com ---- I can't understand why all mysql functions use the \ character to escape special character in queries. THIS IS NOT SQL STANDARD COMPLIANT! To escape the ' character, the real way is to double the character, so it becomes '' (two '). Same thing for all other characters such as % becomes %%. By the current way, when we use Oracle or MSSQL Server by exemple, the result of this function (also MagicQuote) is an error while doing the query, or worste, the query is not protected. select * from users where name = '$login' and password='$password' With $login = "admin" and $password = "dummy' or 1 = 1 --" the query becomes: select * from users where name = 'admin' and password='dummy\' or 1 = 1 --' And then Oracle or MSSQL Server will run the query without understanding the \' as an escaped ' character, so the query is not protected at all! As a result, the user can logon as "admin" even if he don't know the real password!

« previous php.notes (#64078) next »