Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #3839
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Newsgroups | comp.lang.php |
| Subject | Re: i getting this warning |
| Date | 2011-11-21 09:12 -0500 |
| Organization | A noiseless patient Spider |
| Message-ID | <jadm8g$uhj$1@dont-email.me> (permalink) |
| References | (3 earlier) <4EC50CA0.9090009@arnowelzel.de> <ja344f$pcr$1@dont-email.me> <4EC516F2.9070703@arnowelzel.de> <ja36kt$9gt$1@dont-email.me> <4ECA592F.2080704@arnowelzel.de> |
On 11/21/2011 8:59 AM, Arno Welzel wrote:
> Jerry Stuckle, 2011-11-17 15:44:
>
>> On 11/17/2011 9:15 AM, Arno Welzel wrote:
>>> Jerry Stuckle, 2011-11-17 15:01:
>>>
>>>> On 11/17/2011 8:31 AM, Arno Welzel wrote:
>>>>> Denis McMahon, 2011-11-16 16:11:
>>>>>
>>>>>> On Wed, 16 Nov 2011 06:56:21 -0500, Jerry Stuckle wrote:
>>>>>>
>>>>>>> On 11/16/2011 6:17 AM, sri kanth wrote:
>>>>>>
>>>>>>>> $qs=$_REQUEST['id'];
>>>>>>>> $data=mysql_query("select * from tbl_porduct where pid=$qs");
>>>>>>
>>>>>>> Three things.
>>>>>>
>>>>>> You missed "using unescaped user input in a query with no validation or
>>>>>> verification". I know it's only a select, but would you bet that he's
>>>>>> that sloppy with selects and yet rigorous with data changing statements?
>>>>>
>>>>> It does not matter what statement there *is*. Using data from outside in
>>>>> this way makes *everything* possible - this is the typical mistake which
>>>>> makes SQL injection possible!
>>>>>
>>>>>
>>>>> Example:
>>>>>
>>>>> Lets assume $qs is "1;drop tlb_product".
>>>>>
>>>>> $data = mysql_query("select * from tbl_product where pid=$qs");
>>>>>
>>>>> The statement will be expanded to:
>>>>>
>>>>> "select * from tbl_product where pid=1;drop tbl_product"
>>>>>
>>>>> The result will be, that the table tbl_product will be dropped, if the
>>>>> MySQL user has the right to drop tables.
>>>>>
>>>>>
>>>> <snip>
>>>>
>>>> The statement will fail because mysql_query() will not execute multiple
>>>> statements in a single query.
>>>
>>> Generally and in this specific case you are right - but it is possible
>>> and you should never rely on this behaviour.
>>>
>>> See also:<http://php.net/manual/de/function.mysql-query.php>
>>>
>>>
>>
>> You are preaching to the choir here. I'm just pointing out the error in
>> your comments.
>
> And i already agreed with you. So what's your point?
>
> And just tried to explain why the assumption that using multiple queries
> is not a problem, since mysql_query() would fail anyway, may be wrong.
>
>> If you had been reading this newsgroup for the past 8 years or so, you
>> will find many of us (including Denis and myself) have long been
>> proponents of this.
>>
>> But you obviously failed to understand the discussion.
>
> Then ignore my statements.
>
>
No problem. Consider yourself ignorant.
--
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================
Back to comp.lang.php | Previous | Next — Previous in thread | Find similar | Unroll thread
i getting this warning sri kanth <sritullimilli@gmail.com> - 2011-11-16 03:17 -0800
Re: i getting this warning The Natural Philosopher <tnp@invalid.invalid> - 2011-11-16 11:26 +0000
Re: i getting this warning tony@mountifield.org (Tony Mountifield) - 2011-11-16 11:37 +0000
Re: i getting this warning Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-16 06:56 -0500
Re: i getting this warning Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-16 15:11 +0000
Re: i getting this warning Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-16 10:41 -0500
Re: i getting this warning Arno Welzel <usenet@arnowelzel.de> - 2011-11-17 14:31 +0100
Re: i getting this warning Arno Welzel <usenet@arnowelzel.de> - 2011-11-17 14:34 +0100
Re: i getting this warning Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-18 08:02 +0000
Re: i getting this warning The Natural Philosopher <tnp@invalid.invalid> - 2011-11-17 13:39 +0000
Re: i getting this warning Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-17 09:01 -0500
Re: i getting this warning Arno Welzel <usenet@arnowelzel.de> - 2011-11-17 15:15 +0100
Re: i getting this warning Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-17 09:44 -0500
Re: i getting this warning Arno Welzel <usenet@arnowelzel.de> - 2011-11-21 14:59 +0100
Re: i getting this warning Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-21 09:12 -0500
csiph-web