Re: does "quote" DB filter out all dubious characters preventing sql injection?
| From: | Justin Patrin | Date: | Fri, 08 Oct 2004 17:16:08 +0000 |
| Subject: | Re: does "quote" DB filter out all dubious characters preventing sql injection? | ||
| References: | 1 2 3 4 5 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-14816@lists.php.net to get a copy of this message | ||
On Fri, 8 Oct 2004 10:08:51 -0700, Justin Patrin <papercrane@gmail.com> wrote:
> On Fri, 08 Oct 2004 14:04:21 +0200, CirTap <php@serradeil.de> wrote:
> > Hi,
> >
> > > You forgot to point out another option: use placeholders. Read the
> > > PEAR::DB documentation regarding prepare and execute --
> >
> > <snip>
> >
> > > And in the second one:
> > > $sth = $db->query('SELECT * FROM ? WHERE ? = ?', array($table, $col,
> > > $val));
> > >
> > > If the values already contain their quotes (e.g., if magic_quotes is
> > > on), then PEAR::DB won't re-escape them; if not, it will escape them
> > > before placing them in the SQL.
> > >
> >
> > correct me if I'm wrong, but I think the 2nd query should read
> > $db->query('SELECT * FROM ! WHERE ? = ?', array($table, $col, $val));
> > with ! as the placeholder for the tablename, or it will be quoted
> > using "string quotes".
> > I don't think this would have the desired effect :)
> > MySQL (for instance) req. backticks to quote a
tablename.
> >
>
> Actually, to work it should be:
> $db->query('SELECT * FROM ! WHERE ! = ?', array($table, $col, $val));
> However, this doesn't quote the identifiers correctly (it just puts
> them in). Perhaps we need a new prepare type for identifiers? This
> would be very useful for DB_DataObject. It also might be nice to have
> an option to turn off identifier quoting if this is used (it falls
> back to the ! method) since some versions of some DBs don't support
> identifier quoting (old versions of mysql for instance).
>
I've submitted a feature request for this.
http://pear.php.net/bugs/bug.php?id=2483
>
>
> > So quoteIdentifier() may still be necessary in this case (?)
> >
> > I must confess I (still) use DB 1.62, and this behavior may differ in
> > later versions
> >
> > CirTap
> >
--
paperCrane --Justin Patrin--