Re: does "quote" DB filter out all dubious characters preventing sql injection?
| From: | Justin Patrin | Date: | Thu, 07 Oct 2004 21:50:08 +0000 |
| Subject: | Re: does "quote" DB filter out all dubious characters preventing sql injection? | ||
| References: | 1 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-14805@lists.php.net to get a copy of this message | ||
On Thu, 7 Oct 2004 14:43:08 -0700 (PDT), Stowe Spivey
<spiveyspivey@yahoo.com> wrote:
> I'd like to switch to using Pear but need to know how far I need to
> go in securing the use input using DB pkg.
>
Well, the correct function now is quoteSmart(). It completely quotes
the value, making sure that it goes into the DB as given. It stops SQL
injection. For example:
$val = 'blah";DELETE FROM table';
$db = DB::connect($dsn);
$sth = $db->query('SELECT * FROM table WHERE column='.$db->quoteSmart($val));
This will search for "column" equal to exactly the string in $val.
Also, there is a quoteIdentifier function which should be used for
quoting table and column names. You only need to use this if you're
using a reserved word for a table or column name, but it's useful
otherwise too.
$table = 'select';
$column = 'from';
$sth = $db->query('SELECT * FROM '.$db->quoteIdentifier($table).'
WHERE '.$db->quoteIdentifier($col).'='.$db->quoteSmart($val));
--
paperCrane --Justin Patrin--