note 40291 deleted from function.mysql-escape-string by aidan

From: Date: Wed, 11 Aug 2004 14:06:32 +0000
Subject: note 40291 deleted from function.mysql-escape-string by aidan
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-74446@lists.php.net to get a copy of this message
Note Submitter: Slavi Marinov ---- In a normal situation, mysql_query() cannot execute more than one command at a time ( that is, if you pass it a string containing a non-quoted semicolon, mysql_query doesn't run it and produces an error). However, there are certain circumstances ( for example, look at the examples in mysql_query() about performing a batch of queries) that may give tha hacker the ability to smash your database. The example about phones is very smart. Here is one more, that is even more often met ( in fact, I have really encountered sites with this mistake where webmasters do this stupid way of authorization ) : 1. Create a form that has a username and password field 2. in the php script the authorization code is the following $username = $_POST['username']; $password = $_POST['password']; $result = mysql_query("SELECT * FROM Users WHERE Name='$username' AND Password='$password'"); if (mysql_num_rows($result)>0) { echo "Welcome!"; } passing as username the string : ' OR 1=1 AND 1=' produces the same result as with the phones. Whilst the previous example gives you information about phone numbers, this one may open widely a door for hackers to log into your site. So WATCH OUT and call addslashes() everywhere you use input from the user ( you may even use htmlspecialchars() function ). for more information : www.google.com with "mysql injection" and you will see why to backslash your strings :) Good luck! NOTE : this is not only connected to mysql, almost all the stupid script code is vulnerable to SQL injections!

« previous php.notes (#74446) next »