note 39291 deleted from function.mysql-escape-string by nlopess
| From: | nlopess@php.net | Date: | Fri, 23 Jan 2004 19:13:32 +0000 |
| Subject: | note 39291 deleted from function.mysql-escape-string by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-64078@lists.php.net to get a copy of this message | ||
Note Submitter: administrator@manga-torii.com
----
I can't understand why all mysql functions use the \ character to escape special character in
queries.
THIS IS NOT SQL STANDARD COMPLIANT!
To escape the ' character, the real way is to double the character, so it becomes ''
(two '). Same thing for all other characters such as % becomes %%.
By the current way, when we use Oracle or MSSQL Server by exemple, the result of this function (also
MagicQuote) is an error while doing the query, or worste, the query is not protected.
select * from users where name = '$login' and password='$password'
With $login = "admin" and $password = "dummy' or 1 = 1 --" the query
becomes:
select * from users where name = 'admin' and password='dummy\' or 1 = 1 --'
And then Oracle or MSSQL Server will run the query without understanding the \' as an escaped
' character, so the query is not protected at all!
As a result, the user can logon as "admin" even if he don't know the real password!