note 40291 added to function.mysql-escape-string

From: Date: Fri, 27 Feb 2004 14:44:00 +0000
Subject: note 40291 added to function.mysql-escape-string
Groups: php.notes 
Request: Send a blank email to php-notes+get-65888@lists.php.net to get a copy of this message
In a normal situation, mysql_query() cannot execute more than one command at a time ( that is, if you pass it a string containing a non-quoted semicolon, mysql_query doesn't run it and produces an error). However, there are certain circumstances ( for example, look at the examples in mysql_query() about performing a batch of queries) that may give tha hacker the ability to smash your database. The example about phones is very smart. Here is one more, that is even more often met ( in fact, I have really encountered sites with this mistake where webmasters do this stupid way of authorization ) : 1. Create a form that has a username and password field 2. in the php script the authorization code is the following $username = $_POST['username']; $password = $_POST['password']; $result = mysql_query("SELECT * FROM Users WHERE Name='$username' AND Password='$password'"); if (mysql_num_rows($result)>0) { echo "Welcome!"; } passing as username the string : ' OR 1=1 AND 1=' produces the same result as with the phones. Whilst the previous example gives you information about phone numbers, this one may open widely a door for hackers to log into your site. So WATCH OUT and call addslashes() everywhere you use input from the user ( you may even use htmlspecialchars() function ). for more information : www.google.com with "mysql injection" and you will see why to backslash your strings :) Good luck! NOTE : this is not only connected to mysql, almost all the stupid script code is vulnerable to SQL injections! ---- Manual Page -- http://www.php.net/manual/en/function.mysql-escape-string.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+40291 Delete -- http://master.php.net/manage/user-notes.php?action=delete+40291&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+40291&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#65888) next »