RE: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear" -politics aside:-)
| From: | Lukas Smith | Date: | Tue, 19 Mar 2002 23:34:39 +0000 |
| Subject: | RE: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear" -politics aside:-) | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-5052@lists.php.net to get a copy of this message | ||
> > > The other advantage is that you don't need to quote your strings
> > yourself,
> > > avoiding any security problems from tainted data (eg. $_GET and
$_POST
> > > strings).
> >
> > Aeh how so?
> > I am aware of the problem of possible "tainted" data but where does
the
> > data get handled differently from a "normal" query?
>
> It is handled differently because all the right quoting is done behind
> the scenes (either because the DB driver quotes for you, or because it
> uses some bind mechanism). In a normal query you need to do the
quoting
> yourself.
Ah well ...
You mean because you can employ different placeholders like '?' and '!'.
Well this sort of thing is a thing of the past with the inclusion of
Metabase since now you can quite easily specify what type the data is
for queries and prepared queries.
This why you truly don't have to worry about quoting etc. but only about
types.
This still does not solve the issue though, since for example some RDBMS
allow quoted integers and some don't etc.
So I still don't see where prepared queries are the solution to
"tainted" data because not all data will get quoted and therefore you
still have the danger of malicious query tampering.
Or am I missing something here?
Best regards,
Lukas Smith
smith@dybnet.de
_______________________________
DybNet Internet Solutions GbR
Alt Moabit 89
10559 Berlin
Germany
Tel. : +49 30 83 22 50 00
Fax : +49 30 83 22 50 07
www.dybnet.de info@dybnet.de
_______________________________