Re: does "quote" DB filter out all dubious characters preventing sql injection?

From: Date: Fri, 08 Oct 2004 17:16:08 +0000
Subject: Re: does "quote" DB filter out all dubious characters preventing sql injection?
References: 1 2 3 4 5  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-14816@lists.php.net to get a copy of this message
On Fri, 8 Oct 2004 10:08:51 -0700, Justin Patrin <papercrane@gmail.com> wrote: > On Fri, 08 Oct 2004 14:04:21 +0200, CirTap <php@serradeil.de> wrote: > > Hi, > > > > > You forgot to point out another option: use placeholders. Read the > > > PEAR::DB documentation regarding prepare and execute -- > > > > <snip> > > > > > And in the second one: > > > $sth = $db->query('SELECT * FROM ? WHERE ? = ?', array($table, $col, > > > $val)); > > > > > > If the values already contain their quotes (e.g., if magic_quotes is > > > on), then PEAR::DB won't re-escape them; if not, it will escape them > > > before placing them in the SQL. > > > > > > > correct me if I'm wrong, but I think the 2nd query should read > > $db->query('SELECT * FROM ! WHERE ? = ?', array($table, $col, $val)); > > with ! as the placeholder for the tablename, or it will be quoted > > using "string quotes". > > I don't think this would have the desired effect :) > > MySQL (for instance) req. backticks to quote a tablename. > > > > Actually, to work it should be: > $db->query('SELECT * FROM ! WHERE ! = ?', array($table, $col, $val)); > However, this doesn't quote the identifiers correctly (it just puts > them in). Perhaps we need a new prepare type for identifiers? This > would be very useful for DB_DataObject. It also might be nice to have > an option to turn off identifier quoting if this is used (it falls > back to the ! method) since some versions of some DBs don't support > identifier quoting (old versions of mysql for instance). > I've submitted a feature request for this. http://pear.php.net/bugs/bug.php?id=2483 > > > > So quoteIdentifier() may still be necessary in this case (?) > > > > I must confess I (still) use DB 1.62, and this behavior may differ in > > later versions > > > > CirTap > > -- paperCrane --Justin Patrin--

« previous php.pear.general (#14816) next »