note 40291 added to function.mysql-escape-string
| From: | SlaviMarinov at rn2 dot php dot net | Date: | Fri, 27 Feb 2004 14:44:00 +0000 |
| Subject: | note 40291 added to function.mysql-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-65888@lists.php.net to get a copy of this message | ||
In a normal situation, mysql_query() cannot execute more than one command at a time ( that is, if
you pass it a string containing a non-quoted semicolon, mysql_query doesn't run it and produces
an error). However, there are certain circumstances ( for example, look at the examples in
mysql_query() about performing a batch of queries) that may give tha hacker the ability to smash
your database.
The example about phones is very smart. Here is one more, that is even more often met ( in fact, I
have really encountered sites with this mistake where webmasters do this stupid way of authorization
) :
1. Create a form that has a username and password field
2. in the php script the authorization code is the following
$username = $_POST['username'];
$password = $_POST['password'];
$result = mysql_query("SELECT * FROM Users WHERE Name='$username' AND
Password='$password'");
if (mysql_num_rows($result)>0) {
echo "Welcome!";
}
passing as username the string :
' OR 1=1 AND 1='
produces the same result as with the phones.
Whilst the previous example gives you information about phone numbers, this one may open widely a
door for hackers to log into your site. So WATCH OUT and call addslashes() everywhere you use input
from the user ( you may even use htmlspecialchars() function ).
for more information : www.google.com with "mysql injection" and you will see why to
backslash your strings :)
Good luck!
NOTE : this is not only connected to mysql, almost all the stupid script code is vulnerable to SQL
injections!
----
Manual Page -- http://www.php.net/manual/en/function.mysql-escape-string.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+40291
Delete -- http://master.php.net/manage/user-notes.php?action=delete+40291&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+40291&report=yes
Search -- http://master.php.net/manage/user-notes.php