PHP Developers Network

A community of PHP developers offering assistance, advice, discussion, and friendship.
 
Loading
It is currently Wed Dec 19, 2018 11:03 am

All times are UTC - 5 hours




Post new topic Reply to topic  [ 5 posts ] 
Author Message
PostPosted: Mon Mar 17, 2014 6:51 am 
Offline
Forum Newbie

Joined: Sat Mar 08, 2014 8:39 am
Posts: 11
If user input is inserted without modification into an SQL query, then the application becomes vulnerable to SQL injection, like in the following example:

Syntax: [ Download ] [ Hide ]
$unsafe_variable = $_POST['user_input'];


Syntax: [ Download ] [ Hide ]
mysql_query("INSERT INTO table (column) VALUES ('" . $unsafe_variable . "')");

That's because the user can input something like value'); DROP TABLE table;--, and the query becomes:

Syntax: [ Download ] [ Hide ]
INSERT INTO table (column) VALUES('`**`value'); DROP TABLE table;--`**`')

What can be done to prevent this from happening?


Top
 Profile  
 
PostPosted: Mon Mar 17, 2014 6:59 am 
Offline
Moderator
User avatar

Joined: Tue Nov 09, 2010 3:39 pm
Posts: 6424
Location: Montreal, Canada
First of all, stop using mysql_ functions. They've been worst practice for years, are deprecated, and will be removed from the language. That said, the easiest way to prevent SQL injection is to use prepared statements.

_________________
Supported PHP versions No longer supported versions


Top
 Profile  
 
PostPosted: Wed Sep 03, 2014 5:25 pm 
Offline
Spammer :|
User avatar

Joined: Wed Oct 15, 2008 2:35 am
Posts: 6617
Location: WA, USA
resonant wrote:
EDIT: Wow, really? http://pastebin.com/6DxQcPrm <- because double htmlentities() is fail

[php] tags are broken - use [syntax=php] instead.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 5 posts ] 

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 5 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group