Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #4177 > unrolled thread
| Started by | Michael Joel <no@please.com> |
|---|---|
| First post | 2011-12-29 15:55 -0500 |
| Last post | 2012-01-07 15:59 -0500 |
| Articles | 20 on this page of 61 — 10 participants |
Back to article view | Back to comp.lang.php
Magic quotes? Should I still be cautious? Michael Joel <no@please.com> - 2011-12-29 15:55 -0500
Re: Magic quotes? Should I still be cautious? Michael Fesser <netizen@gmx.de> - 2011-12-29 22:04 +0100
Re: Magic quotes? Should I still be cautious? Michael Joel <no@please.com> - 2011-12-29 16:53 -0500
Re: Magic quotes? Should I still be cautious? Michael Joel <no@please.com> - 2011-12-29 17:08 -0500
Re: Magic quotes? Should I still be cautious? Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2011-12-29 23:22 +0100
Re: Magic quotes? Should I still be cautious? "Peter H. Coffin" <hellsop@ninehells.com> - 2011-12-29 17:53 -0600
Re: Magic quotes? Should I still be cautious? Michael Joel <no@please.com> - 2011-12-29 23:32 -0500
Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2011-12-30 12:38 +0100
Re: Magic quotes? Should I still be cautious? Michael Joel <no@please.com> - 2011-12-30 09:52 -0500
Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2012-01-02 15:02 +0100
Re: Magic quotes? Should I still be cautious? Michael Fesser <netizen@gmx.de> - 2011-12-30 13:18 +0100
Re: Magic quotes? Should I still be cautious? "Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid> - 2011-12-30 10:26 +0100
Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2011-12-30 14:42 +0100
Re: Magic quotes? Should I still be cautious? Michael Joel <no@please.com> - 2011-12-30 09:52 -0500
Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-04 15:55 +0100
Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2012-01-05 14:08 +0100
Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-05 14:22 +0100
Re: Magic quotes? Should I still be cautious? The Natural Philosopher <tnp@invalid.invalid> - 2012-01-05 13:36 +0000
Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2012-01-05 15:20 +0100
Re: Magic quotes? Should I still be cautious? The Natural Philosopher <tnp@invalid.invalid> - 2012-01-05 15:49 +0000
Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2012-01-05 14:39 +0100
Re: Magic quotes? Should I still be cautious? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-06 00:28 +0100
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-05 19:36 -0500
Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2012-01-06 11:16 +0100
Re: Magic quotes? Should I still be cautious? Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2012-01-06 12:05 +0100
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-06 08:32 -0500
Re: Magic quotes? Should I still be cautious? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-06 18:18 +0100
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-06 13:04 -0500
Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-08 20:48 +0100
Re: Magic quotes? Should I still be cautious? Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2012-01-06 20:14 +0100
Re: Magic quotes? Should I still be cautious? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-06 20:24 +0100
Re: Magic quotes? Should I still be cautious? The Natural Philosopher <tnp@invalid.invalid> - 2012-01-06 19:34 +0000
Re: Magic quotes? Should I still be cautious? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-06 21:11 +0100
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-06 18:12 -0500
Re: Magic quotes? Should I still be cautious? Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2012-01-07 17:59 +0100
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-07 15:54 -0500
Re: Magic quotes? Should I still be cautious? Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2012-01-08 02:13 +0100
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-07 20:33 -0500
Re: Magic quotes? Should I still be cautious? Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2012-01-09 00:21 +0100
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-08 19:05 -0500
Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-08 20:52 +0100
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-08 15:59 -0500
Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-11 11:00 +0100
Re: Magic quotes? Should I still be cautious? The Natural Philosopher <tnp@invalid.invalid> - 2012-01-11 11:53 +0000
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-11 08:45 -0500
Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-11 15:43 +0100
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-11 08:44 -0500
Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-11 15:47 +0100
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-11 09:51 -0500
Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-11 18:09 +0100
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-11 14:01 -0500
Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-12 08:58 +0100
Re: Magic quotes? Should I still be cautious? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-06 17:41 +0100
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-06 13:05 -0500
Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2012-01-06 11:07 +0100
Re: Magic quotes? Should I still be cautious? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-06 18:05 +0100
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-06 13:07 -0500
Re: Magic quotes? Should I still be cautious? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-06 19:45 +0100
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-06 18:09 -0500
Re: Magic quotes? Should I still be cautious? Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2012-01-07 18:08 +0100
Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-07 15:59 -0500
Page 1 of 4 [1] 2 3 4 Next page →
| From | Michael Joel <no@please.com> |
|---|---|
| Date | 2011-12-29 15:55 -0500 |
| Subject | Magic quotes? Should I still be cautious? |
| Message-ID | <apkpf7pepdppho2ve4fr8nu8u087hmcakl@4ax.com> |
I do not have control of my server (shared server). echo get_magic_quotes_gpc(); returns True. Should I still be cautious and use addslashes/stripslashes in case the hosting company ever decides to change the settings? Thanks Mike
[toc] | [next] | [standalone]
| From | Michael Fesser <netizen@gmx.de> |
|---|---|
| Date | 2011-12-29 22:04 +0100 |
| Message-ID | <0clpf7h20i8q5voh0lt9bfuv8vhaj5n56n@mfesser.de> |
| In reply to | #4177 |
.oO(Michael Joel) >I do not have control of my server (shared server). > >echo get_magic_quotes_gpc(); returns True. >Should I still be cautious and use addslashes/stripslashes in case the >hosting company ever decides to change the settings? Yes. Check if magic quotes are enabled and use stripslashes() if they are to get the raw data. Micha -- http://mfesser.de/blickwinkel
[toc] | [prev] | [next] | [standalone]
| From | Michael Joel <no@please.com> |
|---|---|
| Date | 2011-12-29 16:53 -0500 |
| Message-ID | <baopf7d4v23jtvn1m8si6eou0bks0dtidu@4ax.com> |
| In reply to | #4178 |
On Thu, 29 Dec 2011 22:04:13 +0100, Michael Fesser <netizen@gmx.de> wrote: >.oO(Michael Joel) > >>I do not have control of my server (shared server). >> >>echo get_magic_quotes_gpc(); returns True. >>Should I still be cautious and use addslashes/stripslashes in case the >>hosting company ever decides to change the settings? > >Yes. Check if magic quotes are enabled and use stripslashes() if they >are to get the raw data. > >Micha I have the script written. No I was going to go back and add the addslashes/stripslashes. But - the script is functioning right now without stripping slashes. When I post database data to the page there are no slashes where you would expect to find them. They seem to be removed automatically? Mike
[toc] | [prev] | [next] | [standalone]
| From | Michael Joel <no@please.com> |
|---|---|
| Date | 2011-12-29 17:08 -0500 |
| Message-ID | <85ppf792putq3rj3bg5vm8vure0a8uhr91@4ax.com> |
| In reply to | #4179 |
On Thu, 29 Dec 2011 16:53:17 -0500, Michael Joel <no@please.com> wrote: >On Thu, 29 Dec 2011 22:04:13 +0100, Michael Fesser <netizen@gmx.de> >wrote: > >>.oO(Michael Joel) >> >>>I do not have control of my server (shared server). >>> >>>echo get_magic_quotes_gpc(); returns True. >>>Should I still be cautious and use addslashes/stripslashes in case the >>>hosting company ever decides to change the settings? >> >>Yes. Check if magic quotes are enabled and use stripslashes() if they >>are to get the raw data. >> >>Micha > > >I have the script written. No I was going to go back and add the >addslashes/stripslashes. > >But - the script is functioning right now without stripping slashes. >When I post database data to the page there are no slashes where you >would expect to find them. They seem to be removed automatically? > >Mike Sorry - meant to mention... I did verify magic quote gpc is on. So does it automatically remove slashes as well? Mike
[toc] | [prev] | [next] | [standalone]
| From | Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> |
|---|---|
| Date | 2011-12-29 23:22 +0100 |
| Message-ID | <jdip6i$p01$1@news.albasani.net> |
| In reply to | #4178 |
Michael Fesser schrieb:
> Check if magic quotes are enabled and use stripslashes() if they
> are to get the raw data.
There is also the sybase version of magic quotes which would require a
different kind of treatment. And if the data is an array you have to do
the keys as well, but only on the first level for a multidimensional
array if I remember right and -- well, all this is definitely way too
much trouble.
I prefer using the filter functions (http://de3.php.net/filter). They
allow to access the raw input data and thus to completely bypass any
magic quoting (as well as any modifications of the $_GET etc. arrays
done by the script):
/**
* Read a GPC value.
*
* @param string Name
* @return string|array|null Value or null
*/
function input( $name )
{
$name = str_replace( '.', '_', $name );
foreach ( array( INPUT_GET, INPUT_POST, INPUT_COOKIE ) as $source ):
$value = filter_input( $source, $name, FILTER_UNSAFE_RAW );
if ( $value === false ):
$value = filter_input( $source, $name,
FILTER_UNSAFE_RAW, FILTER_REQUIRE_ARRAY );
endif;
if ( $value !== null and $value !== false ):
return $value;
endif;
endforeach;
}
The above function can be modified to accept an explicit $source as
second argument and do away with the foreach. The first line addresses
the fact that PHP silently converts any dot in a variable name to an
underscore. My function allows using the "dotted" name. Once the value
is retrieved, it must, of course, be properly validated. Although the
filter functions provide such functionality, I prefer to do my own
validation.
Greetings,
Thomas
--
Ce n'est pas parce qu'ils sont nombreux à avoir tort qu'ils ont raison!
(Coluche)
[toc] | [prev] | [next] | [standalone]
| From | "Peter H. Coffin" <hellsop@ninehells.com> |
|---|---|
| Date | 2011-12-29 17:53 -0600 |
| Message-ID | <slrnjfpvb5.51n.hellsop@nibelheim.ninehells.com> |
| In reply to | #4177 |
On Thu, 29 Dec 2011 15:55:10 -0500, Michael Joel wrote:
> I do not have control of my server (shared server).
>
> echo get_magic_quotes_gpc(); returns True.
> Should I still be cautious and use addslashes/stripslashes in case the
> hosting company ever decides to change the settings?
Yup! Just because it's on now doesn't mean it always will be. Never
depend on any setting that you don't control if you can avoid so
depending.
--
Windows gives you a nice view of clouds so you can't see any potentially
useful boot time messages.
-- Bill Hay in the Monastery
[toc] | [prev] | [next] | [standalone]
| From | Michael Joel <no@please.com> |
|---|---|
| Date | 2011-12-29 23:32 -0500 |
| Message-ID | <lffqf75pbd58fnn0vvbhntcoupk1tac0s7@4ax.com> |
| In reply to | #4185 |
On Thu, 29 Dec 2011 17:53:09 -0600, "Peter H. Coffin" <hellsop@ninehells.com> wrote: >On Thu, 29 Dec 2011 15:55:10 -0500, Michael Joel wrote: >> I do not have control of my server (shared server). >> >> echo get_magic_quotes_gpc(); returns True. >> Should I still be cautious and use addslashes/stripslashes in case the >> hosting company ever decides to change the settings? > >Yup! Just because it's on now doesn't mean it always will be. Never >depend on any setting that you don't control if you can avoid so >depending. I just read that magic quotes automatically adds and * removes * slashes. So then my questions is, why test for magic quotes - why not just use addslashes/stripslashes? At worste it appears to be just reprocessing what has just been done for you. The server has it turned on and yet if I simply add/strip without testing it still appears the same way. Mike
[toc] | [prev] | [next] | [standalone]
| From | Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> |
|---|---|
| Date | 2011-12-30 12:38 +0100 |
| Message-ID | <4efda298$0$6898$e4fe514c@news2.news.xs4all.nl> |
| In reply to | #4187 |
On 12/30/2011 5:32 AM, Michael Joel wrote: > On Thu, 29 Dec 2011 17:53:09 -0600, "Peter H. Coffin" > <hellsop@ninehells.com> wrote: > >> On Thu, 29 Dec 2011 15:55:10 -0500, Michael Joel wrote: >>> I do not have control of my server (shared server). >>> >>> echo get_magic_quotes_gpc(); returns True. >>> Should I still be cautious and use addslashes/stripslashes in case the >>> hosting company ever decides to change the settings? >> >> Yup! Just because it's on now doesn't mean it always will be. Never >> depend on any setting that you don't control if you can avoid so >> depending. > > I just read that magic quotes automatically adds and * removes * > slashes. I think you misunderstood. It is wrong. The gpc in magic_quotes_gpc means $_GET / $_POST / $_COOKIE. Values originating from one of those will be escaped by a backslash. Where do you think there are magically removed? Regards, Erwin Moller > > So then my questions is, why test for magic quotes - why not just use > addslashes/stripslashes? At worste it appears to be just reprocessing > what has just been done for you. > > The server has it turned on and yet if I simply add/strip without > testing it still appears the same way. > > Mike -- "That which can be asserted without evidence, can be dismissed without evidence." -- Christopher Hitchens
[toc] | [prev] | [next] | [standalone]
| From | Michael Joel <no@please.com> |
|---|---|
| Date | 2011-12-30 09:52 -0500 |
| Message-ID | <lpjrf7dhnjf1u3o4jf0c66d7itgcpojb7g@4ax.com> |
| In reply to | #4192 |
On Fri, 30 Dec 2011 12:38:01 +0100, Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> wrote: >On 12/30/2011 5:32 AM, Michael Joel wrote: >> On Thu, 29 Dec 2011 17:53:09 -0600, "Peter H. Coffin" >> <hellsop@ninehells.com> wrote: >>.....SNIP............................... >Where do you think there are magically removed? > >>.....SNIP............................... from the book PHP and MYSQL: Web Development (Welling and Thomson). I tested this and it is true. slashes are added and removed automatically. I "imagine" when the vairiables post they are added then when you access the vars they are removed. In any case my tests to see shows the book is correct. As a later poster says though all this is being deprecated so it will become useless. Thanks Mike
[toc] | [prev] | [next] | [standalone]
| From | Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> |
|---|---|
| Date | 2012-01-02 15:02 +0100 |
| Message-ID | <4f01b909$0$6938$e4fe514c@news2.news.xs4all.nl> |
| In reply to | #4195 |
On 12/30/2011 3:52 PM, Michael Joel wrote:
> On Fri, 30 Dec 2011 12:38:01 +0100, Erwin Moller
> <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> wrote:
>
>> On 12/30/2011 5:32 AM, Michael Joel wrote:
>>> On Thu, 29 Dec 2011 17:53:09 -0600, "Peter H. Coffin"
>>> <hellsop@ninehells.com> wrote:
>>> .....SNIP...............................
>> Where do you think there are magically removed?
>>
>>> .....SNIP...............................
>
>
> from the book PHP and MYSQL: Web Development (Welling and Thomson).
> I tested this and it is true.
> slashes are added and removed automatically.
>
> I "imagine" when the vairiables post they are added then when you
> access the vars they are removed. In any case my tests to see shows
> the book is correct.
>
> As a later poster says though all this is being deprecated so it will
> become useless.
>
> Thanks
> Mike
Hi Mike,
I don't know this book, but is seems it did a very poor job explaining
the matter. I'll try to make it clearer.
This is what happens when you have magic_quotes on:
1) Your webserver presents a document with a form to a client.
Lets say it is named signup.html and it contains, amongst others, the
following:
<form action="signup_process.php" Method="post">
Your name: <input type="text" name="firstname" value="">
<input type="submit" value="Post it">
</form>
2) Somebody types in the above form the following:
Joe "hi' Jones
and sends it.
3) At the webserver signup_process.php is invoked.
The environment of PHP contains values in the superglobal $_POST array.
Here (and only here) magic_quotes comes into play.
$_POST["firstname"] contains *Joe "hi' Jones* when magic quotes are off.
$_POST["firstname"] contains *Joe \"hi\' Jones* when magic quotes are on.
(Outer ** added by me, they are not in the variable.)
The only reason those magic quotes were invented is because of the
following: If a lazy/sloppy programmer wanted to use these variables to
insert them into a database, (s)he would do the following:
$SQL =
"INSERT INTO tblusers (firstname) VALUES ('".$_POST["firstname"]."');";
And then execute that statement against some database:
somedb_execute($SQL);
That approach would work fine if the data didn't contain " or ' (and
other naughty characters. Naughty depends on the database in question).
So simply using the values from $_POST would make the receiving script
vulnerable to SQL injection.
A better way (but still not 100% safe) would be to first escape the
received string, like this:
$saferFirstName = addslashes($_POST["firstname"]);
That is why magic_quotes was "invented": It does this addslashes()
automatically for all data that is put into $_GET and $_POST and
$_COOKIE, in case you forget.
So the adding of slashes solves a few problems:
a) It makes it possible to use the character ' or " inside the query.
Note that ' and " are often used in SQL to delimit a string of
characters (for the database field types: text, char, etc).
b) It makes simple SQL injection impossible (Note the word 'simple').
When you read back from the database with the above example like:
SELECT firstname from tblusers;
You will neatly receive *Joe "hi' Jones* as is intended. The slashes are
gone because they were only used to tell the database that the next
character is escaped.
This behavior is probably the reason your book claims that the slashes
are removed, which isn't exactly correct. They were actually never
inserted into the database and only had their use to tell the database
to take the next character literally.
But it was a bad idea for several reasons. To name a few:
a) Escaping only ' and " isn't enough. Different databases have other
character(sequence)s that allow for unintended action when executed with
only addslashes().
b) It gives newbies a false sense of security. They might think
something like "I have those magic quotes on, so my application is safe
for SQL injection.", which it isn't.
Hope that helped. :-)
Make sure you understand the issues involved, or you will be bitten in
the back later.
It really helped me to understand it all by hacking my own applications.
It is worth your time, and many hacks and cracks you can read about on
the net make sense when you do it yourself.
Regards,
Erwin Moller
--
"That which can be asserted without evidence, can be dismissed without
evidence."
-- Christopher Hitchens
[toc] | [prev] | [next] | [standalone]
| From | Michael Fesser <netizen@gmx.de> |
|---|---|
| Date | 2011-12-30 13:18 +0100 |
| Message-ID | <9rarf75kiosj8smkdmaveooqhj79072lu0@mfesser.de> |
| In reply to | #4187 |
.oO(Michael Joel) >So then my questions is, why test for magic quotes - why not just use >addslashes/stripslashes? At worste it appears to be just reprocessing >what has just been done for you. Magic quotes are not secure and will be completely removed in the near future. Even addslashes/stripslashes are not secure, because they don't escape all necessary characters for database input. So the general rule is: Test for magic quotes if you can't disable them, remove them if necessary with stripslashes(), then apply the appropriate escaping functions wherever necessary (e.g. mysql_real_escape_string()). Micha -- http://mfesser.de/blickwinkel
[toc] | [prev] | [next] | [standalone]
| From | "Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid> |
|---|---|
| Date | 2011-12-30 10:26 +0100 |
| Message-ID | <jdk04h$cap$1@dont-email.me> |
| In reply to | #4177 |
El 29/12/2011 21:55, Michael Joel escribió/wrote: > I do not have control of my server (shared server). > > echo get_magic_quotes_gpc(); returns True. > Should I still be cautious and use addslashes/stripslashes in case the > hosting company ever decides to change the settings? I'm not fully sure of what you want to know, but I personally find that magic quotes makes coding more difficult and annoying. I normally do the following: 1. Change settings to disable all these annoying "magic" features: magic quotes, register globals... This involves either .htaccess or a custom php.ini file, depending on the server API. (Many of these features cannot be changed in PHP code because they are already in affect when the script starts executing.) 2. Add a few verifications to my bootstrap file (the site's settings file) so I'm notified when settings are wrong. 3. Code normally. -- -- http://alvaro.es - Álvaro G. Vicario - Burgos, Spain -- Mi sitio sobre programación web: http://borrame.com -- Mi web de humor satinado: http://www.demogracia.com --
[toc] | [prev] | [next] | [standalone]
| From | Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> |
|---|---|
| Date | 2011-12-30 14:42 +0100 |
| Message-ID | <4efdbfd2$0$6879$e4fe514c@news2.news.xs4all.nl> |
| In reply to | #4177 |
On 12/29/2011 9:55 PM, Michael Joel wrote:
> I do not have control of my server (shared server).
>
> echo get_magic_quotes_gpc(); returns True.
> Should I still be cautious and use addslashes/stripslashes in case the
> hosting company ever decides to change the settings?
>
> Thanks
> Mike
Hi Mike,
To sum up all the responses so far:
1) Avoid all use of magic_quotes in your code. Do not rely on it.
2) If you want your programs to be prepared for magic_quotes, as in
older shared hosting environments like yours, write a small function to
wrap the test in, like:
function getRawGPCValue($someGPCStr){
if (get_magic_quotes_gpc() === 1){
return stripslashes($someGPCStr);
} else {
return $someGPCStr;
}
}
And then when you need a value from $_POST, simply do:
$firstName = getRawGPCValue($_POST("firstname"));
You might want to use a shorter functionname. ;-)
3) When you need to use the value from sources like GPC, simply do the
right thing with the *raw* data.
For example:
a) When you expect an integer, don't mind the escaping, simply cast it
to integer:
$userid = (int)$_POST["userid"];
(You might want to add additional checks of course, like rnage of the
number, if $_POST["userid"] is set at all, etc.)
b) When you want to output it to HTML:
$firstName = getRawGPCValue($_POST("firstname"));
echo htmlentities($firstName);
For more details like charset/encoding read here:
http://nl3.php.net/manual/en/function.htmlentities.php
c) When you want to insert characterdata into your database:
Use the right escape function suitable for your database, or use
something like PDO.
eg: mysql_real_escape_string() for mysql
pg_escape_literal() for Postgres.
etc.
d) When using in an URL, url encode the raw data.
etc. etc. etc.
Bottomline: Make sure you have the raw (real) data, and use the
appropriate approach before using.
There is no "magic" solution that solves all possible situations,
despite names like "magic_quotes".
Escaping of strings works differently for URLs, HTML, databaseX, databaseY,
Tip:
When the encoding of some string is different than for example the
receiving database, have a look at iconv. It saved me a few headaches.
http://nl3.php.net/manual/en/function.iconv.php
Good luck!
regards,
Erwin Moller
--
"That which can be asserted without evidence, can be dismissed without
evidence."
-- Christopher Hitchens
[toc] | [prev] | [next] | [standalone]
| From | Michael Joel <no@please.com> |
|---|---|
| Date | 2011-12-30 09:52 -0500 |
| Message-ID | <n0krf71c9bk0bkko643a4k8db9m1s1v3tn@4ax.com> |
| In reply to | #4194 |
On Fri, 30 Dec 2011 14:42:43 +0100, Erwin Moller
<Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> wrote:
>On 12/29/2011 9:55 PM, Michael Joel wrote:
>> I do not have control of my server (shared server).
>>
>> echo get_magic_quotes_gpc(); returns True.
>> Should I still be cautious and use addslashes/stripslashes in case the
>> hosting company ever decides to change the settings?
>>
>> Thanks
>> Mike
>
>Hi Mike,
>
>To sum up all the responses so far:
>1) Avoid all use of magic_quotes in your code. Do not rely on it.
>2) If you want your programs to be prepared for magic_quotes, as in
>older shared hosting environments like yours, write a small function to
>wrap the test in, like:
>
>function getRawGPCValue($someGPCStr){
> if (get_magic_quotes_gpc() === 1){
> return stripslashes($someGPCStr);
> } else {
> return $someGPCStr;
> }
>}
>
>And then when you need a value from $_POST, simply do:
>$firstName = getRawGPCValue($_POST("firstname"));
>
>You might want to use a shorter functionname. ;-)
>
>
>3) When you need to use the value from sources like GPC, simply do the
>right thing with the *raw* data.
>
>For example:
>a) When you expect an integer, don't mind the escaping, simply cast it
>to integer:
>$userid = (int)$_POST["userid"];
>(You might want to add additional checks of course, like rnage of the
>number, if $_POST["userid"] is set at all, etc.)
>
>b) When you want to output it to HTML:
>$firstName = getRawGPCValue($_POST("firstname"));
>echo htmlentities($firstName);
>For more details like charset/encoding read here:
>http://nl3.php.net/manual/en/function.htmlentities.php
>
>c) When you want to insert characterdata into your database:
>Use the right escape function suitable for your database, or use
>something like PDO.
>eg: mysql_real_escape_string() for mysql
>pg_escape_literal() for Postgres.
>etc.
>
>d) When using in an URL, url encode the raw data.
>
>
>etc. etc. etc.
>
>
>Bottomline: Make sure you have the raw (real) data, and use the
>appropriate approach before using.
>There is no "magic" solution that solves all possible situations,
>despite names like "magic_quotes".
>Escaping of strings works differently for URLs, HTML, databaseX, databaseY,
>
>Tip:
>When the encoding of some string is different than for example the
>receiving database, have a look at iconv. It saved me a few headaches.
>http://nl3.php.net/manual/en/function.iconv.php
>
>Good luck!
>
>regards,
>Erwin Moller
Thanks - and thanks all.
This is a lot of information. I plan to go back and adjust the code to
comply better.
Thanks again
Mike
[toc] | [prev] | [next] | [standalone]
| From | Arno Welzel <usenet@arnowelzel.de> |
|---|---|
| Date | 2012-01-04 15:55 +0100 |
| Message-ID | <4F046877.3080409@arnowelzel.de> |
| In reply to | #4177 |
Michael Joel, 2011-12-29 21:55: > I do not have control of my server (shared server). > > echo get_magic_quotes_gpc(); returns True. > Should I still be cautious and use addslashes/stripslashes in case the > hosting company ever decides to change the settings? I assume magic quotes to be disabled and in the past i used the following code fragment to be safe: <http://arnowelzel.de/wiki/en/web/php_magicquotes> -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de
[toc] | [prev] | [next] | [standalone]
| From | Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> |
|---|---|
| Date | 2012-01-05 14:08 +0100 |
| Message-ID | <4f05a0b4$0$6924$e4fe514c@news2.news.xs4all.nl> |
| In reply to | #4219 |
On 1/4/2012 3:55 PM, Arno Welzel wrote:
> Michael Joel, 2011-12-29 21:55:
>
>> I do not have control of my server (shared server).
>>
>> echo get_magic_quotes_gpc(); returns True.
>> Should I still be cautious and use addslashes/stripslashes in case the
>> hosting company ever decides to change the settings?
>
> I assume magic quotes to be disabled and in the past i used the
> following code fragment to be safe:
>
> <http://arnowelzel.de/wiki/en/web/php_magicquotes>
>
>
Hi Arnold,
That is a lot of overhead on each request.
It loops over all superglobals and calls stripslashes on each of them
(in case magic_quotes is on).
You also do this for $_ENV and $_SERVER which seems strange to me
because magic_quotes only affects cookie/post/get.
magic_quotes_gpc Affects HTTP Request data (GET, POST, and COOKIE).
source: http://nl3.php.net/manual/en/security.magicquotes.what.php
And $_REQUEST should be avoided anyway in all situation (in my humble
opinion) for various reasons. But if you use it, it should indeed be
added to your list in your approach.
Regards,
Erwin Moller
Your code:
===========================================
ini_set('magic_quotes_runtime', 0);
if(get_magic_quotes_gpc())
{
$superglobals=array(
"_REQUEST",
"_GET",
"_POST",
"_COOKIE",
"_ENV",
"_SERVER");
foreach($superglobals as $globalname)
{
foreach($GLOBALS[$globalname] as $name => $value)
{
if(!is_array($value))
{
$GLOBALS[$globalname][$name] = stripslashes($value);
}
}
}
unset($superglobals);
}
===========================================
--
"That which can be asserted without evidence, can be dismissed without
evidence."
-- Christopher Hitchens
[toc] | [prev] | [next] | [standalone]
| From | Arno Welzel <usenet@arnowelzel.de> |
|---|---|
| Date | 2012-01-05 14:22 +0100 |
| Message-ID | <4F05A411.7000009@arnowelzel.de> |
| In reply to | #4220 |
Erwin Moller, 2012-01-05 14:08: > On 1/4/2012 3:55 PM, Arno Welzel wrote: >> Michael Joel, 2011-12-29 21:55: >> >>> I do not have control of my server (shared server). >>> >>> echo get_magic_quotes_gpc(); returns True. >>> Should I still be cautious and use addslashes/stripslashes in case the >>> hosting company ever decides to change the settings? >> >> I assume magic quotes to be disabled and in the past i used the >> following code fragment to be safe: >> >> <http://arnowelzel.de/wiki/en/web/php_magicquotes> >> >> > > Hi Arnold, Just Arno - not Arnold ;-) > That is a lot of overhead on each request. I know - and this is only meant to be a workaround for existing code which can not be easily adopted to handle Magic Quotes and the PHP configuration can not be changed. > And $_REQUEST should be avoided anyway in all situation (in my humble > opinion) for various reasons. But if you use it, it should indeed be > added to your list in your approach. I'm not sure, if it's enough to modify $_GET, $_POST etc. if further parts of a script use $_REQUEST - therefore i added $_REQUEST to be sure. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2012-01-05 13:36 +0000 |
| Message-ID | <je491o$tu0$1@news.albasani.net> |
| In reply to | #4221 |
Arno Welzel wrote: > Erwin Moller, 2012-01-05 14:08: > >> On 1/4/2012 3:55 PM, Arno Welzel wrote: >>> Michael Joel, 2011-12-29 21:55: >>> >>>> I do not have control of my server (shared server). >>>> >>>> echo get_magic_quotes_gpc(); returns True. >>>> Should I still be cautious and use addslashes/stripslashes in case the >>>> hosting company ever decides to change the settings? >>> I assume magic quotes to be disabled and in the past i used the >>> following code fragment to be safe: >>> >>> <http://arnowelzel.de/wiki/en/web/php_magicquotes> >>> >>> >> Hi Arnold, > > Just Arno - not Arnold ;-) > > >> That is a lot of overhead on each request. > > I know - and this is only meant to be a workaround for existing code > which can not be easily adopted to handle Magic Quotes and the PHP > configuration can not be changed. > >> And $_REQUEST should be avoided anyway in all situation (in my humble >> opinion) for various reasons. But if you use it, it should indeed be >> added to your list in your approach. > > I'm not sure, if it's enough to modify $_GET, $_POST etc. if further > parts of a script use $_REQUEST - therefore i added $_REQUEST to be sure. > > I am interested in this, because in general I leave magic quotes on because some old code relies on it on some of my sites.. Is this comment still true? - its from the PHP manual "I have discovered that my host doesn't like either of the following directives in the .htaccess file: php_flag magic_quotes_gpc Off php_value magic_quotes_gpc Off However, there is another way to disable this setting even if you don't have access to the server configuration - you can put a php.ini file in the directory where your scripts are with the directive: magic_quotes_gpc = Off However, these does not propogate unlike .htaccess rules, so if you launch from a sub-directory, you need the php.ini file in each directory you have as script entry points." If so it, gives another option to override server defaults.
[toc] | [prev] | [next] | [standalone]
| From | Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> |
|---|---|
| Date | 2012-01-05 15:20 +0100 |
| Message-ID | <4f05b1b3$0$6886$e4fe514c@news2.news.xs4all.nl> |
| In reply to | #4222 |
On 1/5/2012 2:36 PM, The Natural Philosopher wrote: > Arno Welzel wrote: >> Erwin Moller, 2012-01-05 14:08: >> >>> On 1/4/2012 3:55 PM, Arno Welzel wrote: >>>> Michael Joel, 2011-12-29 21:55: >>>> >>>>> I do not have control of my server (shared server). >>>>> >>>>> echo get_magic_quotes_gpc(); returns True. >>>>> Should I still be cautious and use addslashes/stripslashes in case the >>>>> hosting company ever decides to change the settings? >>>> I assume magic quotes to be disabled and in the past i used the >>>> following code fragment to be safe: >>>> >>>> <http://arnowelzel.de/wiki/en/web/php_magicquotes> >>>> >>>> >>> Hi Arnold, >> >> Just Arno - not Arnold ;-) >> >> >>> That is a lot of overhead on each request. >> >> I know - and this is only meant to be a workaround for existing code >> which can not be easily adopted to handle Magic Quotes and the PHP >> configuration can not be changed. >> >>> And $_REQUEST should be avoided anyway in all situation (in my humble >>> opinion) for various reasons. But if you use it, it should indeed be >>> added to your list in your approach. >> >> I'm not sure, if it's enough to modify $_GET, $_POST etc. if further >> parts of a script use $_REQUEST - therefore i added $_REQUEST to be sure. >> >> > I am interested in this, because in general I leave magic quotes on > because some old code relies on it on some of my sites.. Hi NP, I feel your pain. I am in the same situation. :-( (I have an old PHP4.3 machine under my control with magic_quotes on.) > > > Is this comment still true? - its from the PHP manual > > "I have discovered that my host doesn't like either of the following > directives in the .htaccess file: > > php_flag magic_quotes_gpc Off > php_value magic_quotes_gpc Off > > However, there is another way to disable this setting even if you don't > have access to the server configuration - you can put a php.ini file in > the directory where your scripts are with the directive: > > magic_quotes_gpc = Off > > However, these does not propogate unlike .htaccess rules, so if you > launch from a sub-directory, you need the php.ini file in each directory > you have as script entry points." > > > If so it, gives another option to override server defaults. I wouldn't bet on that trick to work everywhere. It seems to me that depends on the way PHP and/or Apache is set up. Much safer is simply wrap a simple function around $_POST["whatever"] that tests for the real situation. Or use Arno's trick, which is a little heavier on the server because it strips more than needed. The advantage of Arno's approach is of course that you don't have to adjust existing code: you can simply enforce magic_quotes or shut them down. I do prefer a wrapperfunction. That way you have no server dependencies in your PHP code. Well, at least not for magic_quotes that is. ;-) Regards, Erwin Moller -- "That which can be asserted without evidence, can be dismissed without evidence." -- Christopher Hitchens
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2012-01-05 15:49 +0000 |
| Message-ID | <je4gpn$g52$1@news.albasani.net> |
| In reply to | #4224 |
Erwin Moller wrote: > On 1/5/2012 2:36 PM, The Natural Philosopher wrote: >> Arno Welzel wrote: >>> Erwin Moller, 2012-01-05 14:08: >>> >>>> On 1/4/2012 3:55 PM, Arno Welzel wrote: >>>>> Michael Joel, 2011-12-29 21:55: >>>>> >>>>>> I do not have control of my server (shared server). >>>>>> >>>>>> echo get_magic_quotes_gpc(); returns True. >>>>>> Should I still be cautious and use addslashes/stripslashes in case >>>>>> the >>>>>> hosting company ever decides to change the settings? >>>>> I assume magic quotes to be disabled and in the past i used the >>>>> following code fragment to be safe: >>>>> >>>>> <http://arnowelzel.de/wiki/en/web/php_magicquotes> >>>>> >>>>> >>>> Hi Arnold, >>> >>> Just Arno - not Arnold ;-) >>> >>> >>>> That is a lot of overhead on each request. >>> >>> I know - and this is only meant to be a workaround for existing code >>> which can not be easily adopted to handle Magic Quotes and the PHP >>> configuration can not be changed. >>> >>>> And $_REQUEST should be avoided anyway in all situation (in my humble >>>> opinion) for various reasons. But if you use it, it should indeed be >>>> added to your list in your approach. >>> >>> I'm not sure, if it's enough to modify $_GET, $_POST etc. if further >>> parts of a script use $_REQUEST - therefore i added $_REQUEST to be >>> sure. >>> >>> >> I am interested in this, because in general I leave magic quotes on >> because some old code relies on it on some of my sites.. > > Hi NP, > > I feel your pain. I am in the same situation. :-( > (I have an old PHP4.3 machine under my control with magic_quotes on.) > > >> >> >> Is this comment still true? - its from the PHP manual >> >> "I have discovered that my host doesn't like either of the following >> directives in the .htaccess file: >> >> php_flag magic_quotes_gpc Off >> php_value magic_quotes_gpc Off >> >> However, there is another way to disable this setting even if you don't >> have access to the server configuration - you can put a php.ini file in >> the directory where your scripts are with the directive: >> >> magic_quotes_gpc = Off >> >> However, these does not propogate unlike .htaccess rules, so if you >> launch from a sub-directory, you need the php.ini file in each directory >> you have as script entry points." >> >> >> If so it, gives another option to override server defaults. > > I wouldn't bet on that trick to work everywhere. > It seems to me that depends on the way PHP and/or Apache is set up. > well that on my new cheap virtual server is entirely UP TO ME!! I cannot believe how little it costs, either. <$200 a year (about £160 uk IIRC) I am limited on RAM and disk space, and total byte transfers but CPU power is - massive. As is network speed. Its all RAIDED.. And a quick rsync backs it up on the server here every night..in case. Best of all with my admin center here on a fixed IP address, I can set the firewall to let ME have unlimited access to it. I actually NFS mount the web sites when I am working on them and edit the files directly if I feel lucky. No more FTP uploads. The cherry on the cake was putting a pass through for its IP address into my admin network here and setting up a print queue that prints directly to the printer on my desk! Apart from a slight speed issue saving files, it's like it was a machine here in the office. (except when the power went out last night, it stayed up) If you have more than a few websites its well worth doing this I feel. > Much safer is simply wrap a simple function around $_POST["whatever"] > that tests for the real situation. > Or use Arno's trick, which is a little heavier on the server because it > strips more than needed. > The advantage of Arno's approach is of course that you don't have to > adjust existing code: you can simply enforce magic_quotes or shut them > down. > > I do prefer a wrapperfunction. That way you have no server dependencies > in your PHP code. > Well, at least not for magic_quotes that is. ;-) > > Regards, > Erwin Moller > > IF I was stick with a server setup that meant I had no other choice, I would. My situation is different however. I am looking for the simplest way to make it a per site option, and not a global one. Given its my server to do what I like with..
[toc] | [prev] | [next] | [standalone]
Page 1 of 4 [1] 2 3 4 Next page →
Back to top | Article view | comp.lang.php
csiph-web