RE: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear" -politics aside:-)

From: Date: Wed, 20 Mar 2002 06:33:14 +0000
Subject: RE: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear" -politics aside:-)
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-5055@lists.php.net to get a copy of this message
On Wed, 2002-03-20 at 00:34, Lukas Smith wrote: > > > > The other advantage is that you don't need to quote your strings > > > yourself, > > > > avoiding any security problems from tainted data (eg. $_GET and > $_POST > > > > strings). > > > > > > Aeh how so? > > > I am aware of the problem of possible "tainted" data but where does > the > > > data get handled differently from a "normal" query? > > > > It is handled differently because all the right quoting is done behind > > the scenes (either because the DB driver quotes for you, or because it > > uses some bind mechanism). In a normal query you need to do the > quoting > > yourself. > > Ah well ... > You mean because you can employ different placeholders like '?' and '!'. > Well this sort of thing is a thing of the past with the inclusion of > Metabase since now you can quite easily specify what type the data is > for queries and prepared queries. > > This why you truly don't have to worry about quoting etc. but only about > types. > > This still does not solve the issue though, since for example some RDBMS > allow quoted integers and some don't etc. > > So I still don't see where prepared queries are the solution to > "tainted" data because not all data will get quoted and therefore you > still have the danger of malicious query tampering. > > Or am I missing something here? Aha! We're misunderstanding eachother, I'm talking about escaping special characters in data before embedding it in the query. As for types, yes you're right. Today PEAR's prepare emulation puts ampersands and escapes only string data, so you have control over that by passing data with the right PHP types. Ideally we should have some knowledge of the types in the database, but I'm not sure if that is realistic. - Stig

« previous php.pear.dev (#5055) next »