Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!weretis.net!feeder4.news.weretis.net!eternal-september.org!feeder.eternal-september.org!.POSTED!not-for-mail From: Arno Welzel Newsgroups: comp.lang.php Subject: Re: i getting this warning Date: Mon, 21 Nov 2011 14:59:11 +0100 Organization: A noiseless patient Spider Lines: 73 Message-ID: <4ECA592F.2080704@arnowelzel.de> References: <616578.124.1321442274513.JavaMail.geo-discussion-forums@prmf13> <4ec3d299$0$28440$a8266bb1@newsreader.readnews.com> <4EC50CA0.9090009@arnowelzel.de> <4EC516F2.9070703@arnowelzel.de> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Injection-Info: mx04.eternal-september.org; posting-host="dd4uQGf4fHOQcq7/hg1u1Q"; logging-data="24415"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX185IzqOyKR2C8NdcKDu/kBsNIP6XRlKd7k=" User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20111105 Thunderbird/8.0 In-Reply-To: Cancel-Lock: sha1:+tLzQmQmwYVd2K6cAO3sClaK7Ok= Xref: x330-a1.tempe.blueboxinc.net comp.lang.php:3837 Jerry Stuckle, 2011-11-17 15:44: > On 11/17/2011 9:15 AM, Arno Welzel wrote: >> Jerry Stuckle, 2011-11-17 15:01: >> >>> On 11/17/2011 8:31 AM, Arno Welzel wrote: >>>> Denis McMahon, 2011-11-16 16:11: >>>> >>>>> On Wed, 16 Nov 2011 06:56:21 -0500, Jerry Stuckle wrote: >>>>> >>>>>> On 11/16/2011 6:17 AM, sri kanth wrote: >>>>> >>>>>>> $qs=$_REQUEST['id']; >>>>>>> $data=mysql_query("select * from tbl_porduct where pid=$qs"); >>>>> >>>>>> Three things. >>>>> >>>>> You missed "using unescaped user input in a query with no validation or >>>>> verification". I know it's only a select, but would you bet that he's >>>>> that sloppy with selects and yet rigorous with data changing statements? >>>> >>>> It does not matter what statement there *is*. Using data from outside in >>>> this way makes *everything* possible - this is the typical mistake which >>>> makes SQL injection possible! >>>> >>>> >>>> Example: >>>> >>>> Lets assume $qs is "1;drop tlb_product". >>>> >>>> $data = mysql_query("select * from tbl_product where pid=$qs"); >>>> >>>> The statement will be expanded to: >>>> >>>> "select * from tbl_product where pid=1;drop tbl_product" >>>> >>>> The result will be, that the table tbl_product will be dropped, if the >>>> MySQL user has the right to drop tables. >>>> >>>> >>> >>> >>> The statement will fail because mysql_query() will not execute multiple >>> statements in a single query. >> >> Generally and in this specific case you are right - but it is possible >> and you should never rely on this behaviour. >> >> See also: >> >> > > You are preaching to the choir here. I'm just pointing out the error in > your comments. And i already agreed with you. So what's your point? And just tried to explain why the assumption that using multiple queries is not a problem, since mysql_query() would fail anyway, may be wrong. > If you had been reading this newsgroup for the past 8 years or so, you > will find many of us (including Denis and myself) have long been > proponents of this. > > But you obviously failed to understand the discussion. Then ignore my statements. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de