Re: does "quote" DB filter out all dubious characters preventing sql injection?

From: Date: Fri, 08 Oct 2004 17:08:51 +0000
Subject: Re: does "quote" DB filter out all dubious characters preventing sql injection?
References: 1 2 3 4  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-14815@lists.php.net to get a copy of this message
On Fri, 08 Oct 2004 14:04:21 +0200, CirTap <php@serradeil.de> wrote: > Hi, > > > You forgot to point out another option: use placeholders. Read the > > PEAR::DB documentation regarding prepare and execute -- > > <snip> > > > And in the second one: > > $sth = $db->query('SELECT * FROM ? WHERE ? = ?', array($table, $col, $val)); > > > > If the values already contain their quotes (e.g., if magic_quotes is > > on), then PEAR::DB won't re-escape them; if not, it will escape them > > before placing them in the SQL. > > > > correct me if I'm wrong, but I think the 2nd query should read > $db->query('SELECT * FROM ! WHERE ? = ?', array($table, $col, $val)); > with ! as the placeholder for the tablename, or it will be quoted > using "string quotes". > I don't think this would have the desired effect :) > MySQL (for instance) req. backticks to quote a tablename. > Actually, to work it should be: $db->query('SELECT * FROM ! WHERE ! = ?', array($table, $col, $val)); However, this doesn't quote the identifiers correctly (it just puts them in). Perhaps we need a new prepare type for identifiers? This would be very useful for DB_DataObject. It also might be nice to have an option to turn off identifier quoting if this is used (it falls back to the ! method) since some versions of some DBs don't support identifier quoting (old versions of mysql for instance). > So quoteIdentifier() may still be necessary in this case (?) > > I must confess I (still) use DB 1.62, and this behavior may differ in > later versions > > CirTap > > -- > PEAR General Mailing List (http://pear.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php > > > !DSPAM:41668326222241323138487! > > -- paperCrane --Justin Patrin--

« previous php.pear.general (#14815) next »