note 52415 added to function.preg-grep
| From: | erik dot dobecky at NOSPAM dot fi-us dot com | Date: | Sat, 30 Apr 2005 04:16:00 +0000 |
| Subject: | note 52415 added to function.preg-grep | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-88781@lists.php.net to get a copy of this message | ||
A useful way that we have developed filters against SQL injection attempts is to preg_grep the
$_REQUEST global with the following regular expression (regex):
'/[\'")]* *[oO][rR] *.*(.)(.) *= *\\2(?:--)?\\1?/'
which is used simply as:
<?php
$SQLInjectionRegex = '/[\'")]* *[oO][rR] *.*(.)(.) *= *\\2(?:--)?\\1?/';
$suspiciousQueryItems = preg_grep($SQLInjectionRegex, $_REQUEST);
?>
which matches any of the following (case insensitive, a=any char) strings (entirely):
' or 1=1--
" or 1=1--
or 1=1--
' or 'a'='a
" or "a"="a
') or ('a'='a
----
Manual Page -- http://www.php.net/manual/en/function.preg-grep.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+52415
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+52415&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+52415&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+52415&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+52415&report=yes&reason=useless
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+52415&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+52415&report=yes
Search -- http://master.php.net/manage/user-notes.php