RE: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear" -politics aside:-)
| From: | Stig S. Bakken | Date: | Wed, 20 Mar 2002 06:33:14 +0000 |
| Subject: | RE: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear" -politics aside:-) | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-5055@lists.php.net to get a copy of this message | ||
On Wed, 2002-03-20 at 00:34, Lukas Smith wrote:
> > > > The other advantage is that you don't need to quote your strings
> > > yourself,
> > > > avoiding any security problems from tainted data (eg. $_GET and
> $_POST
> > > > strings).
> > >
> > > Aeh how so?
> > > I am aware of the problem of possible "tainted" data but where does
> the
> > > data get handled differently from a "normal" query?
> >
> > It is handled differently because all the right quoting is done behind
> > the scenes (either because the DB driver quotes for you, or because it
> > uses some bind mechanism). In a normal query you need to do the
> quoting
> > yourself.
>
> Ah well ...
> You mean because you can employ different placeholders like '?' and '!'.
> Well this sort of thing is a thing of the past with the inclusion of
> Metabase since now you can quite easily specify what type the data is
> for queries and prepared queries.
>
> This why you truly don't have to worry about quoting etc. but only about
> types.
>
> This still does not solve the issue though, since for example some RDBMS
> allow quoted integers and some don't etc.
>
> So I still don't see where prepared queries are the solution to
> "tainted" data because not all data will get quoted and therefore you
> still have the danger of malicious query tampering.
>
> Or am I missing something here?
Aha! We're misunderstanding eachother, I'm talking about escaping
special characters in data before embedding it in the query. As for
types, yes you're right. Today PEAR's prepare emulation puts ampersands
and escapes only string data, so you have control over that by passing
data with the right PHP types. Ideally we should have some knowledge of
the types in the database, but I'm not sure if that is realistic.
- Stig