Path: csiph.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail From: Arno Welzel Newsgroups: comp.lang.php Subject: Re: PHP processing steps to apply to a URL to make it safe Date: Wed, 17 Feb 2016 19:08:48 +0100 Lines: 23 Message-ID: <56C4B730.3030608@arnowelzel.de> References: <56c47913$0$24153$e4fe514c@news.xs4all.nl> <56C47E05.10508@arnowelzel.de> <56c48103$0$24054$e4fe514c@news.xs4all.nl> <56C487FA.1070401@arnowelzel.de> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-Trace: individual.net yBY0nbnsvsDIDHbsqe1IFAem+VAkeUL7kq/VGwQX5CZcc6KM1r Cancel-Lock: sha1:5WWg4kKkcqoGNmFrvqq+segUMlU= In-Reply-To: Xref: csiph.com comp.lang.php:16469 Christoph M. Becker schrieb am 2016-02-17 um 16:38: > Arno Welzel wrote: > >> How does an *URL* itself cause an SQL injection? At least a PHP script >> has to use the provided values and use it within an SQL statement. > > Consider that *some* URL is supplied and expected as input *parameter*. > Unless the parameter is validated or sanitized, there could be a > security issue. Sure - but the question of the OP was not "how can I validate/sanitize input parameters" but "how can I make an URL safe" - and since an URL itself is not "safe" or "unsafe" the OP has to explain what he wants to achieve. Otherwise one can only recommend general guidelines how to avoid security problems - but this has nothing to do with URLs itself at all. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de http://fahrradzukunft.de