Re: does "quote" DB filter out all dubious characters preventing sql injection?
| From: | Justin Patrin | Date: | Fri, 08 Oct 2004 17:08:51 +0000 |
| Subject: | Re: does "quote" DB filter out all dubious characters preventing sql injection? | ||
| References: | 1 2 3 4 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-14815@lists.php.net to get a copy of this message | ||
On Fri, 08 Oct 2004 14:04:21 +0200, CirTap <php@serradeil.de> wrote:
> Hi,
>
> > You forgot to point out another option: use placeholders. Read the
> > PEAR::DB documentation regarding prepare and execute --
>
> <snip>
>
> > And in the second one:
> > $sth = $db->query('SELECT * FROM ? WHERE ? = ?', array($table, $col, $val));
> >
> > If the values already contain their quotes (e.g., if magic_quotes is
> > on), then PEAR::DB won't re-escape them; if not, it will escape them
> > before placing them in the SQL.
> >
>
> correct me if I'm wrong, but I think the 2nd query should read
> $db->query('SELECT * FROM ! WHERE ? = ?', array($table, $col, $val));
> with ! as the placeholder for the tablename, or it will be quoted
> using "string quotes".
> I don't think this would have the desired effect :)
> MySQL (for instance) req. backticks to quote a
tablename.
>
Actually, to work it should be:
$db->query('SELECT * FROM ! WHERE ! = ?', array($table, $col, $val));
However, this doesn't quote the identifiers correctly (it just puts
them in). Perhaps we need a new prepare type for identifiers? This
would be very useful for DB_DataObject. It also might be nice to have
an option to turn off identifier quoting if this is used (it falls
back to the ! method) since some versions of some DBs don't support
identifier quoting (old versions of mysql for instance).
> So quoteIdentifier() may still be necessary in this case (?)
>
> I must confess I (still) use DB 1.62, and this behavior may differ in
> later versions
>
> CirTap
>
> --
> PEAR General Mailing List (http://pear.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
> !DSPAM:41668326222241323138487!
>
>
--
paperCrane --Justin Patrin--