Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #4177 > unrolled thread

Magic quotes? Should I still be cautious?

Started byMichael Joel <no@please.com>
First post2011-12-29 15:55 -0500
Last post2012-01-07 15:59 -0500
Articles 20 on this page of 61 — 10 participants

Back to article view | Back to comp.lang.php


Contents

  Magic quotes? Should I still be cautious? Michael Joel <no@please.com> - 2011-12-29 15:55 -0500
    Re: Magic quotes? Should I still be cautious? Michael Fesser <netizen@gmx.de> - 2011-12-29 22:04 +0100
      Re: Magic quotes? Should I still be cautious? Michael Joel <no@please.com> - 2011-12-29 16:53 -0500
        Re: Magic quotes? Should I still be cautious? Michael Joel <no@please.com> - 2011-12-29 17:08 -0500
      Re: Magic quotes? Should I still be cautious? Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2011-12-29 23:22 +0100
    Re: Magic quotes? Should I still be cautious? "Peter H. Coffin" <hellsop@ninehells.com> - 2011-12-29 17:53 -0600
      Re: Magic quotes? Should I still be cautious? Michael Joel <no@please.com> - 2011-12-29 23:32 -0500
        Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2011-12-30 12:38 +0100
          Re: Magic quotes? Should I still be cautious? Michael Joel <no@please.com> - 2011-12-30 09:52 -0500
            Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2012-01-02 15:02 +0100
        Re: Magic quotes? Should I still be cautious? Michael Fesser <netizen@gmx.de> - 2011-12-30 13:18 +0100
    Re: Magic quotes? Should I still be cautious? "Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid> - 2011-12-30 10:26 +0100
    Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2011-12-30 14:42 +0100
      Re: Magic quotes? Should I still be cautious? Michael Joel <no@please.com> - 2011-12-30 09:52 -0500
    Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-04 15:55 +0100
      Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2012-01-05 14:08 +0100
        Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-05 14:22 +0100
          Re: Magic quotes? Should I still be cautious? The Natural Philosopher <tnp@invalid.invalid> - 2012-01-05 13:36 +0000
            Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2012-01-05 15:20 +0100
              Re: Magic quotes? Should I still be cautious? The Natural Philosopher <tnp@invalid.invalid> - 2012-01-05 15:49 +0000
          Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2012-01-05 14:39 +0100
        Re: Magic quotes? Should I still be cautious? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-06 00:28 +0100
          Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-05 19:36 -0500
            Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2012-01-06 11:16 +0100
            Re: Magic quotes? Should I still be cautious? Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2012-01-06 12:05 +0100
              Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-06 08:32 -0500
                Re: Magic quotes? Should I still be cautious? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-06 18:18 +0100
                  Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-06 13:04 -0500
                  Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-08 20:48 +0100
                Re: Magic quotes? Should I still be cautious? Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2012-01-06 20:14 +0100
                  Re: Magic quotes? Should I still be cautious? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-06 20:24 +0100
                  Re: Magic quotes? Should I still be cautious? The Natural Philosopher <tnp@invalid.invalid> - 2012-01-06 19:34 +0000
                    Re: Magic quotes? Should I still be cautious? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-06 21:11 +0100
                  Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-06 18:12 -0500
                    Re: Magic quotes? Should I still be cautious? Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2012-01-07 17:59 +0100
                      Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-07 15:54 -0500
                        Re: Magic quotes? Should I still be cautious? Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2012-01-08 02:13 +0100
                          Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-07 20:33 -0500
                            Re: Magic quotes? Should I still be cautious? Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2012-01-09 00:21 +0100
                              Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-08 19:05 -0500
                    Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-08 20:52 +0100
                      Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-08 15:59 -0500
                        Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-11 11:00 +0100
                          Re: Magic quotes? Should I still be cautious? The Natural Philosopher <tnp@invalid.invalid> - 2012-01-11 11:53 +0000
                            Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-11 08:45 -0500
                            Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-11 15:43 +0100
                          Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-11 08:44 -0500
                            Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-11 15:47 +0100
                              Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-11 09:51 -0500
                                Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-11 18:09 +0100
                                  Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-11 14:01 -0500
                                    Re: Magic quotes? Should I still be cautious? Arno Welzel <usenet@arnowelzel.de> - 2012-01-12 08:58 +0100
            Re: Magic quotes? Should I still be cautious? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-06 17:41 +0100
              Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-06 13:05 -0500
          Re: Magic quotes? Should I still be cautious? Erwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> - 2012-01-06 11:07 +0100
            Re: Magic quotes? Should I still be cautious? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-06 18:05 +0100
              Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-06 13:07 -0500
                Re: Magic quotes? Should I still be cautious? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-06 19:45 +0100
                  Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-06 18:09 -0500
                    Re: Magic quotes? Should I still be cautious? Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2012-01-07 18:08 +0100
                      Re: Magic quotes? Should I still be cautious? Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-07 15:59 -0500

Page 1 of 4  [1] 2 3 4  Next page →


#4177 — Magic quotes? Should I still be cautious?

FromMichael Joel <no@please.com>
Date2011-12-29 15:55 -0500
SubjectMagic quotes? Should I still be cautious?
Message-ID<apkpf7pepdppho2ve4fr8nu8u087hmcakl@4ax.com>
I do not have control of my server (shared server).

echo get_magic_quotes_gpc(); returns True.
Should I still be cautious and use addslashes/stripslashes in case the
hosting company ever decides to change the settings?

Thanks
Mike

[toc] | [next] | [standalone]


#4178

FromMichael Fesser <netizen@gmx.de>
Date2011-12-29 22:04 +0100
Message-ID<0clpf7h20i8q5voh0lt9bfuv8vhaj5n56n@mfesser.de>
In reply to#4177
.oO(Michael Joel)

>I do not have control of my server (shared server).
>
>echo get_magic_quotes_gpc(); returns True.
>Should I still be cautious and use addslashes/stripslashes in case the
>hosting company ever decides to change the settings?

Yes. Check if magic quotes are enabled and use stripslashes() if they
are to get the raw data.

Micha

-- 
http://mfesser.de/blickwinkel

[toc] | [prev] | [next] | [standalone]


#4179

FromMichael Joel <no@please.com>
Date2011-12-29 16:53 -0500
Message-ID<baopf7d4v23jtvn1m8si6eou0bks0dtidu@4ax.com>
In reply to#4178
On Thu, 29 Dec 2011 22:04:13 +0100, Michael Fesser <netizen@gmx.de>
wrote:

>.oO(Michael Joel)
>
>>I do not have control of my server (shared server).
>>
>>echo get_magic_quotes_gpc(); returns True.
>>Should I still be cautious and use addslashes/stripslashes in case the
>>hosting company ever decides to change the settings?
>
>Yes. Check if magic quotes are enabled and use stripslashes() if they
>are to get the raw data.
>
>Micha


I have the script written. No I was going to go back and add the
addslashes/stripslashes.

But - the script is functioning right now without stripping slashes.
When I post database data to the page there are no slashes where you
would expect to find them. They seem to be removed automatically?

Mike

[toc] | [prev] | [next] | [standalone]


#4180

FromMichael Joel <no@please.com>
Date2011-12-29 17:08 -0500
Message-ID<85ppf792putq3rj3bg5vm8vure0a8uhr91@4ax.com>
In reply to#4179
On Thu, 29 Dec 2011 16:53:17 -0500, Michael Joel <no@please.com>
wrote:

>On Thu, 29 Dec 2011 22:04:13 +0100, Michael Fesser <netizen@gmx.de>
>wrote:
>
>>.oO(Michael Joel)
>>
>>>I do not have control of my server (shared server).
>>>
>>>echo get_magic_quotes_gpc(); returns True.
>>>Should I still be cautious and use addslashes/stripslashes in case the
>>>hosting company ever decides to change the settings?
>>
>>Yes. Check if magic quotes are enabled and use stripslashes() if they
>>are to get the raw data.
>>
>>Micha
>
>
>I have the script written. No I was going to go back and add the
>addslashes/stripslashes.
>
>But - the script is functioning right now without stripping slashes.
>When I post database data to the page there are no slashes where you
>would expect to find them. They seem to be removed automatically?
>
>Mike

Sorry - meant to mention... I did verify magic quote gpc is on. So
does it automatically remove slashes as well?

Mike

[toc] | [prev] | [next] | [standalone]


#4181

FromThomas Mlynarczyk <thomas@mlynarczyk-webdesign.de>
Date2011-12-29 23:22 +0100
Message-ID<jdip6i$p01$1@news.albasani.net>
In reply to#4178
Michael Fesser schrieb:
> Check if magic quotes are enabled and use stripslashes() if they
> are to get the raw data.

There is also the sybase version of magic quotes which would require a 
different kind of treatment. And if the data is an array you have to do 
the keys as well, but only on the first level for a multidimensional 
array if I remember right and -- well, all this is definitely way too 
much trouble.

I prefer using the filter functions (http://de3.php.net/filter). They 
allow to access the raw input data and thus to completely bypass any 
magic quoting (as well as any modifications of the $_GET etc. arrays 
done by the script):

/**
  *  Read a GPC value.
  *
  *  @param    string              Name
  *  @return   string|array|null   Value or null
  */
function input( $name )
{
   $name = str_replace( '.', '_', $name );
   foreach ( array( INPUT_GET, INPUT_POST, INPUT_COOKIE ) as $source ):
     $value = filter_input( $source, $name, FILTER_UNSAFE_RAW );
     if ( $value === false ):
       $value = filter_input( $source, $name,
         FILTER_UNSAFE_RAW, FILTER_REQUIRE_ARRAY );
     endif;
     if ( $value !== null and $value !== false ):
       return $value;
     endif;
   endforeach;
}

The above function can be modified to accept an explicit $source as 
second argument and do away with the foreach. The first line addresses 
the fact that PHP silently converts any dot in a variable name to an 
underscore. My function allows using the "dotted" name. Once the value 
is retrieved, it must, of course, be properly validated. Although the 
filter functions provide such functionality, I prefer to do my own 
validation.

Greetings,
Thomas


-- 
Ce n'est pas parce qu'ils sont nombreux à avoir tort qu'ils ont raison!
(Coluche)

[toc] | [prev] | [next] | [standalone]


#4185

From"Peter H. Coffin" <hellsop@ninehells.com>
Date2011-12-29 17:53 -0600
Message-ID<slrnjfpvb5.51n.hellsop@nibelheim.ninehells.com>
In reply to#4177
On Thu, 29 Dec 2011 15:55:10 -0500, Michael Joel wrote:
> I do not have control of my server (shared server).
>
> echo get_magic_quotes_gpc(); returns True.
> Should I still be cautious and use addslashes/stripslashes in case the
> hosting company ever decides to change the settings?

Yup! Just because it's on now doesn't mean it always will be. Never
depend on any setting that you don't control if you can avoid so
depending.

-- 
Windows gives you a nice view of clouds so you can't see any potentially
useful boot time messages.
              -- Bill Hay in the Monastery

[toc] | [prev] | [next] | [standalone]


#4187

FromMichael Joel <no@please.com>
Date2011-12-29 23:32 -0500
Message-ID<lffqf75pbd58fnn0vvbhntcoupk1tac0s7@4ax.com>
In reply to#4185
On Thu, 29 Dec 2011 17:53:09 -0600, "Peter H. Coffin"
<hellsop@ninehells.com> wrote:

>On Thu, 29 Dec 2011 15:55:10 -0500, Michael Joel wrote:
>> I do not have control of my server (shared server).
>>
>> echo get_magic_quotes_gpc(); returns True.
>> Should I still be cautious and use addslashes/stripslashes in case the
>> hosting company ever decides to change the settings?
>
>Yup! Just because it's on now doesn't mean it always will be. Never
>depend on any setting that you don't control if you can avoid so
>depending.

I just read that magic quotes automatically adds and * removes *
slashes.

So then my questions is, why test for magic quotes - why not just use
addslashes/stripslashes? At worste it appears to be just reprocessing
what has just been done for you.

The server has it turned on and yet if I simply add/strip without
testing it still appears the same way.

Mike

[toc] | [prev] | [next] | [standalone]


#4192

FromErwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com>
Date2011-12-30 12:38 +0100
Message-ID<4efda298$0$6898$e4fe514c@news2.news.xs4all.nl>
In reply to#4187
On 12/30/2011 5:32 AM, Michael Joel wrote:
> On Thu, 29 Dec 2011 17:53:09 -0600, "Peter H. Coffin"
> <hellsop@ninehells.com>  wrote:
>
>> On Thu, 29 Dec 2011 15:55:10 -0500, Michael Joel wrote:
>>> I do not have control of my server (shared server).
>>>
>>> echo get_magic_quotes_gpc(); returns True.
>>> Should I still be cautious and use addslashes/stripslashes in case the
>>> hosting company ever decides to change the settings?
>>
>> Yup! Just because it's on now doesn't mean it always will be. Never
>> depend on any setting that you don't control if you can avoid so
>> depending.
>
> I just read that magic quotes automatically adds and * removes *
> slashes.

I think you misunderstood.
It is wrong.
The gpc in magic_quotes_gpc means $_GET / $_POST / $_COOKIE.
Values originating from one of those will be escaped by a backslash.

Where do you think there are magically removed?

Regards,
Erwin Moller



>
> So then my questions is, why test for magic quotes - why not just use
> addslashes/stripslashes? At worste it appears to be just reprocessing
> what has just been done for you.
>
> The server has it turned on and yet if I simply add/strip without
> testing it still appears the same way.
>
> Mike


-- 
"That which can be asserted without evidence, can be dismissed without 
evidence."
-- Christopher Hitchens

[toc] | [prev] | [next] | [standalone]


#4195

FromMichael Joel <no@please.com>
Date2011-12-30 09:52 -0500
Message-ID<lpjrf7dhnjf1u3o4jf0c66d7itgcpojb7g@4ax.com>
In reply to#4192
On Fri, 30 Dec 2011 12:38:01 +0100, Erwin Moller
<Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> wrote:

>On 12/30/2011 5:32 AM, Michael Joel wrote:
>> On Thu, 29 Dec 2011 17:53:09 -0600, "Peter H. Coffin"
>> <hellsop@ninehells.com>  wrote:
>>.....SNIP...............................
>Where do you think there are magically removed?
>
>>.....SNIP...............................


from the book PHP and MYSQL: Web Development (Welling and Thomson).
I tested this and it is true.
slashes are added and removed automatically.

I "imagine" when the vairiables post they are added then when you
access the vars they are removed. In any case my tests to see shows
the book is correct.

As a later poster says though all this is being deprecated so it will
become useless.

Thanks
Mike

[toc] | [prev] | [next] | [standalone]


#4207

FromErwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com>
Date2012-01-02 15:02 +0100
Message-ID<4f01b909$0$6938$e4fe514c@news2.news.xs4all.nl>
In reply to#4195
On 12/30/2011 3:52 PM, Michael Joel wrote:
> On Fri, 30 Dec 2011 12:38:01 +0100, Erwin Moller
> <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com>  wrote:
>
>> On 12/30/2011 5:32 AM, Michael Joel wrote:
>>> On Thu, 29 Dec 2011 17:53:09 -0600, "Peter H. Coffin"
>>> <hellsop@ninehells.com>   wrote:
>>> .....SNIP...............................
>> Where do you think there are magically removed?
>>
>>> .....SNIP...............................
>
>
> from the book PHP and MYSQL: Web Development (Welling and Thomson).
> I tested this and it is true.
> slashes are added and removed automatically.
>
> I "imagine" when the vairiables post they are added then when you
> access the vars they are removed. In any case my tests to see shows
> the book is correct.
>
> As a later poster says though all this is being deprecated so it will
> become useless.
>
> Thanks
> Mike

Hi Mike,

I don't know this book, but is seems it did a very poor job explaining 
the matter. I'll try to make it clearer.

This is what happens when you have magic_quotes on:

1) Your webserver presents a document with a form to a client.
Lets say it is named signup.html and it contains, amongst others, the 
following:
<form action="signup_process.php" Method="post">
Your name: <input type="text" name="firstname" value="">
<input type="submit" value="Post it">
</form>

2) Somebody types in the above form the following:
Joe "hi' Jones
and sends it.

3) At the webserver signup_process.php is invoked.
The environment of PHP contains values in the superglobal $_POST array.
Here (and only here) magic_quotes comes into play.

$_POST["firstname"] contains *Joe "hi' Jones* when magic quotes are off.
$_POST["firstname"] contains *Joe \"hi\' Jones* when magic quotes are on.

(Outer ** added by me, they are not in the variable.)

The only reason those magic quotes were invented is because of the 
following: If a lazy/sloppy programmer wanted to use these variables to 
insert them into a database, (s)he would do the following:

$SQL =
"INSERT INTO tblusers (firstname) VALUES ('".$_POST["firstname"]."');";

And then execute that statement against some database:
somedb_execute($SQL);

That approach would work fine if the data didn't contain " or ' (and 
other naughty characters. Naughty depends on the database in question).

So simply using the values from $_POST would make the receiving script 
vulnerable to SQL injection.

A better way (but still not 100% safe) would be to first escape the 
received string, like this:
$saferFirstName = addslashes($_POST["firstname"]);

That is why magic_quotes was "invented": It does this addslashes() 
automatically for all data that is put into $_GET and $_POST and 
$_COOKIE, in case you forget.

So the adding of slashes solves a few problems:
a) It makes it possible to use the character ' or " inside the query.
Note that ' and " are often used in SQL to delimit a string of 
characters (for the database field types: text, char, etc).
b) It makes simple SQL injection impossible (Note the word 'simple').

When you read back from the database with the above example like:
SELECT firstname from tblusers;
You will neatly receive *Joe "hi' Jones* as is intended. The slashes are 
gone because they were only used to tell the database that the next 
character is escaped.
This behavior is probably the reason your book claims that the slashes 
are removed, which isn't exactly correct. They were actually never 
inserted into the database and only had their use to tell the database 
to take the next character literally.

But it was a bad idea for several reasons. To name a few:
a) Escaping only ' and " isn't enough. Different databases have other 
character(sequence)s that allow for unintended action when executed with 
only addslashes().
b) It gives newbies a false sense of security. They might think 
something like "I have those magic quotes on, so my application is safe 
for SQL injection.", which it isn't.

Hope that helped. :-)
Make sure you understand the issues involved, or you will be bitten in 
the back later.
It really helped me to understand it all by hacking my own applications. 
It is worth your time, and many hacks and cracks you can read about on 
the net make sense when you do it yourself.

Regards,
Erwin Moller

-- 
"That which can be asserted without evidence, can be dismissed without 
evidence."
-- Christopher Hitchens

[toc] | [prev] | [next] | [standalone]


#4193

FromMichael Fesser <netizen@gmx.de>
Date2011-12-30 13:18 +0100
Message-ID<9rarf75kiosj8smkdmaveooqhj79072lu0@mfesser.de>
In reply to#4187
.oO(Michael Joel)

>So then my questions is, why test for magic quotes - why not just use
>addslashes/stripslashes? At worste it appears to be just reprocessing
>what has just been done for you.

Magic quotes are not secure and will be completely removed in the near
future. Even addslashes/stripslashes are not secure, because they don't
escape all necessary characters for database input.

So the general rule is: Test for magic quotes if you can't disable them,
remove them if necessary with stripslashes(), then apply the appropriate
escaping functions wherever necessary (e.g. mysql_real_escape_string()).

Micha

-- 
http://mfesser.de/blickwinkel

[toc] | [prev] | [next] | [standalone]


#4189

From"Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid>
Date2011-12-30 10:26 +0100
Message-ID<jdk04h$cap$1@dont-email.me>
In reply to#4177
El 29/12/2011 21:55, Michael Joel escribió/wrote:
> I do not have control of my server (shared server).
>
> echo get_magic_quotes_gpc(); returns True.
> Should I still be cautious and use addslashes/stripslashes in case the
> hosting company ever decides to change the settings?

I'm not fully sure of what you want to know, but I personally find that 
magic quotes makes coding more difficult and annoying. I normally do the 
following:

1. Change settings to disable all these annoying "magic" features: magic 
quotes, register globals... This involves either .htaccess or a custom 
php.ini file, depending on the server API. (Many of these features 
cannot be changed in PHP code because they are already in affect when 
the script starts executing.)

2. Add a few verifications to my bootstrap file (the site's settings 
file) so I'm notified when settings are wrong.

3. Code normally.


-- 
-- http://alvaro.es - Álvaro G. Vicario - Burgos, Spain
-- Mi sitio sobre programación web: http://borrame.com
-- Mi web de humor satinado: http://www.demogracia.com
--

[toc] | [prev] | [next] | [standalone]


#4194

FromErwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com>
Date2011-12-30 14:42 +0100
Message-ID<4efdbfd2$0$6879$e4fe514c@news2.news.xs4all.nl>
In reply to#4177
On 12/29/2011 9:55 PM, Michael Joel wrote:
> I do not have control of my server (shared server).
>
> echo get_magic_quotes_gpc(); returns True.
> Should I still be cautious and use addslashes/stripslashes in case the
> hosting company ever decides to change the settings?
>
> Thanks
> Mike

Hi Mike,

To sum up all the responses so far:
1) Avoid all use of magic_quotes in your code. Do not rely on it.
2) If you want your programs to be prepared for magic_quotes, as in 
older shared hosting environments like yours, write a small function to 
wrap the test in, like:

function getRawGPCValue($someGPCStr){
   if (get_magic_quotes_gpc() === 1){
    return stripslashes($someGPCStr);
   } else {
    return $someGPCStr;
   }
}

And then when you need a value from $_POST, simply do:
$firstName = getRawGPCValue($_POST("firstname"));

You might want to use a shorter functionname. ;-)


3) When you need to use the value from sources like GPC, simply do the 
right thing with the *raw* data.

For example:
a) When you expect an integer, don't mind the escaping, simply cast it 
to integer:
$userid = (int)$_POST["userid"];
(You might want to add additional checks of course, like rnage of the 
number, if $_POST["userid"] is set at all, etc.)

b) When you want to output it to HTML:
$firstName = getRawGPCValue($_POST("firstname"));
echo htmlentities($firstName);
For more details like charset/encoding read here:
http://nl3.php.net/manual/en/function.htmlentities.php

c) When you want to insert characterdata into your database:
Use the right escape function suitable for your database, or use 
something like PDO.
eg: mysql_real_escape_string() for mysql
pg_escape_literal() for Postgres.
etc.

d) When using in an URL, url encode the raw data.


etc. etc. etc.


Bottomline: Make sure you have the raw (real) data, and use the 
appropriate approach before using.
There is no "magic" solution that solves all possible situations, 
despite names like "magic_quotes".
Escaping of strings works differently for URLs, HTML, databaseX, databaseY,

Tip:
When the encoding of some string is different than for example the 
receiving database, have a look at iconv. It saved me a few headaches.
http://nl3.php.net/manual/en/function.iconv.php

Good luck!

regards,
Erwin Moller


-- 
"That which can be asserted without evidence, can be dismissed without 
evidence."
-- Christopher Hitchens

[toc] | [prev] | [next] | [standalone]


#4196

FromMichael Joel <no@please.com>
Date2011-12-30 09:52 -0500
Message-ID<n0krf71c9bk0bkko643a4k8db9m1s1v3tn@4ax.com>
In reply to#4194
On Fri, 30 Dec 2011 14:42:43 +0100, Erwin Moller
<Since_humans_read_this_I_am_spammed_too_much@spamyourself.com> wrote:

>On 12/29/2011 9:55 PM, Michael Joel wrote:
>> I do not have control of my server (shared server).
>>
>> echo get_magic_quotes_gpc(); returns True.
>> Should I still be cautious and use addslashes/stripslashes in case the
>> hosting company ever decides to change the settings?
>>
>> Thanks
>> Mike
>
>Hi Mike,
>
>To sum up all the responses so far:
>1) Avoid all use of magic_quotes in your code. Do not rely on it.
>2) If you want your programs to be prepared for magic_quotes, as in 
>older shared hosting environments like yours, write a small function to 
>wrap the test in, like:
>
>function getRawGPCValue($someGPCStr){
>   if (get_magic_quotes_gpc() === 1){
>    return stripslashes($someGPCStr);
>   } else {
>    return $someGPCStr;
>   }
>}
>
>And then when you need a value from $_POST, simply do:
>$firstName = getRawGPCValue($_POST("firstname"));
>
>You might want to use a shorter functionname. ;-)
>
>
>3) When you need to use the value from sources like GPC, simply do the 
>right thing with the *raw* data.
>
>For example:
>a) When you expect an integer, don't mind the escaping, simply cast it 
>to integer:
>$userid = (int)$_POST["userid"];
>(You might want to add additional checks of course, like rnage of the 
>number, if $_POST["userid"] is set at all, etc.)
>
>b) When you want to output it to HTML:
>$firstName = getRawGPCValue($_POST("firstname"));
>echo htmlentities($firstName);
>For more details like charset/encoding read here:
>http://nl3.php.net/manual/en/function.htmlentities.php
>
>c) When you want to insert characterdata into your database:
>Use the right escape function suitable for your database, or use 
>something like PDO.
>eg: mysql_real_escape_string() for mysql
>pg_escape_literal() for Postgres.
>etc.
>
>d) When using in an URL, url encode the raw data.
>
>
>etc. etc. etc.
>
>
>Bottomline: Make sure you have the raw (real) data, and use the 
>appropriate approach before using.
>There is no "magic" solution that solves all possible situations, 
>despite names like "magic_quotes".
>Escaping of strings works differently for URLs, HTML, databaseX, databaseY,
>
>Tip:
>When the encoding of some string is different than for example the 
>receiving database, have a look at iconv. It saved me a few headaches.
>http://nl3.php.net/manual/en/function.iconv.php
>
>Good luck!
>
>regards,
>Erwin Moller


Thanks - and thanks all.
This is a lot of information. I plan to go back and adjust the code to
comply better.

Thanks again
Mike

[toc] | [prev] | [next] | [standalone]


#4219

FromArno Welzel <usenet@arnowelzel.de>
Date2012-01-04 15:55 +0100
Message-ID<4F046877.3080409@arnowelzel.de>
In reply to#4177
Michael Joel, 2011-12-29 21:55:

> I do not have control of my server (shared server).
> 
> echo get_magic_quotes_gpc(); returns True.
> Should I still be cautious and use addslashes/stripslashes in case the
> hosting company ever decides to change the settings?

I assume magic quotes to be disabled and in the past i used the
following code fragment to be safe:

<http://arnowelzel.de/wiki/en/web/php_magicquotes>


-- 
Arno Welzel
http://arnowelzel.de
http://de-rec-fahrrad.de

[toc] | [prev] | [next] | [standalone]


#4220

FromErwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com>
Date2012-01-05 14:08 +0100
Message-ID<4f05a0b4$0$6924$e4fe514c@news2.news.xs4all.nl>
In reply to#4219
On 1/4/2012 3:55 PM, Arno Welzel wrote:
> Michael Joel, 2011-12-29 21:55:
>
>> I do not have control of my server (shared server).
>>
>> echo get_magic_quotes_gpc(); returns True.
>> Should I still be cautious and use addslashes/stripslashes in case the
>> hosting company ever decides to change the settings?
>
> I assume magic quotes to be disabled and in the past i used the
> following code fragment to be safe:
>
> <http://arnowelzel.de/wiki/en/web/php_magicquotes>
>
>

Hi Arnold,

That is a lot of overhead on each request.
It loops over all superglobals and calls stripslashes on each of them 
(in case magic_quotes is on).
You also do this for $_ENV and $_SERVER which seems strange to me 
because magic_quotes only affects cookie/post/get.

magic_quotes_gpc Affects HTTP Request data (GET, POST, and COOKIE).
source: http://nl3.php.net/manual/en/security.magicquotes.what.php

And $_REQUEST should be avoided anyway in all situation (in my humble 
opinion) for various reasons. But if you use it, it should indeed be 
added to your list in your approach.

Regards,
Erwin Moller


Your code:
===========================================
ini_set('magic_quotes_runtime', 0);

if(get_magic_quotes_gpc())
{
   $superglobals=array(
     "_REQUEST",
     "_GET",
     "_POST",
     "_COOKIE",
     "_ENV",
     "_SERVER");

   foreach($superglobals as $globalname)
   {
     foreach($GLOBALS[$globalname] as $name => $value)
     {
       if(!is_array($value))
       {
         $GLOBALS[$globalname][$name] = stripslashes($value);
       }
     }
   }
   unset($superglobals);
}
===========================================



-- 
"That which can be asserted without evidence, can be dismissed without 
evidence."
-- Christopher Hitchens

[toc] | [prev] | [next] | [standalone]


#4221

FromArno Welzel <usenet@arnowelzel.de>
Date2012-01-05 14:22 +0100
Message-ID<4F05A411.7000009@arnowelzel.de>
In reply to#4220
Erwin Moller, 2012-01-05 14:08:

> On 1/4/2012 3:55 PM, Arno Welzel wrote:
>> Michael Joel, 2011-12-29 21:55:
>>
>>> I do not have control of my server (shared server).
>>>
>>> echo get_magic_quotes_gpc(); returns True.
>>> Should I still be cautious and use addslashes/stripslashes in case the
>>> hosting company ever decides to change the settings?
>>
>> I assume magic quotes to be disabled and in the past i used the
>> following code fragment to be safe:
>>
>> <http://arnowelzel.de/wiki/en/web/php_magicquotes>
>>
>>
> 
> Hi Arnold,

Just Arno - not Arnold ;-)


> That is a lot of overhead on each request.

I know - and this is only meant to be a workaround for existing code
which can not be easily adopted to handle Magic Quotes and the PHP
configuration can not be changed.

> And $_REQUEST should be avoided anyway in all situation (in my humble 
> opinion) for various reasons. But if you use it, it should indeed be 
> added to your list in your approach.

I'm not sure, if it's enough to modify $_GET, $_POST etc. if further
parts of a script use $_REQUEST - therefore i added $_REQUEST to be sure.


-- 
Arno Welzel
http://arnowelzel.de
http://de-rec-fahrrad.de

[toc] | [prev] | [next] | [standalone]


#4222

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2012-01-05 13:36 +0000
Message-ID<je491o$tu0$1@news.albasani.net>
In reply to#4221
Arno Welzel wrote:
> Erwin Moller, 2012-01-05 14:08:
> 
>> On 1/4/2012 3:55 PM, Arno Welzel wrote:
>>> Michael Joel, 2011-12-29 21:55:
>>>
>>>> I do not have control of my server (shared server).
>>>>
>>>> echo get_magic_quotes_gpc(); returns True.
>>>> Should I still be cautious and use addslashes/stripslashes in case the
>>>> hosting company ever decides to change the settings?
>>> I assume magic quotes to be disabled and in the past i used the
>>> following code fragment to be safe:
>>>
>>> <http://arnowelzel.de/wiki/en/web/php_magicquotes>
>>>
>>>
>> Hi Arnold,
> 
> Just Arno - not Arnold ;-)
> 
> 
>> That is a lot of overhead on each request.
> 
> I know - and this is only meant to be a workaround for existing code
> which can not be easily adopted to handle Magic Quotes and the PHP
> configuration can not be changed.
> 
>> And $_REQUEST should be avoided anyway in all situation (in my humble 
>> opinion) for various reasons. But if you use it, it should indeed be 
>> added to your list in your approach.
> 
> I'm not sure, if it's enough to modify $_GET, $_POST etc. if further
> parts of a script use $_REQUEST - therefore i added $_REQUEST to be sure.
> 
> 
I am interested in this, because in general I leave magic quotes on 
because some old code relies on it on some of my sites..


Is this comment still true? - its from the PHP manual

"I have discovered that my host doesn't like either of the following 
directives in the .htaccess file:

php_flag magic_quotes_gpc Off
php_value magic_quotes_gpc Off

However, there is another way to disable this setting even if you don't 
have access to the server configuration - you can put a php.ini file in 
the directory where your scripts are with the directive:

magic_quotes_gpc = Off

However, these does not propogate unlike  .htaccess rules, so if you 
launch from a sub-directory, you need the php.ini file in each directory 
you have as script entry points."


If so it, gives another option to override server defaults.

[toc] | [prev] | [next] | [standalone]


#4224

FromErwin Moller <Since_humans_read_this_I_am_spammed_too_much@spamyourself.com>
Date2012-01-05 15:20 +0100
Message-ID<4f05b1b3$0$6886$e4fe514c@news2.news.xs4all.nl>
In reply to#4222
On 1/5/2012 2:36 PM, The Natural Philosopher wrote:
> Arno Welzel wrote:
>> Erwin Moller, 2012-01-05 14:08:
>>
>>> On 1/4/2012 3:55 PM, Arno Welzel wrote:
>>>> Michael Joel, 2011-12-29 21:55:
>>>>
>>>>> I do not have control of my server (shared server).
>>>>>
>>>>> echo get_magic_quotes_gpc(); returns True.
>>>>> Should I still be cautious and use addslashes/stripslashes in case the
>>>>> hosting company ever decides to change the settings?
>>>> I assume magic quotes to be disabled and in the past i used the
>>>> following code fragment to be safe:
>>>>
>>>> <http://arnowelzel.de/wiki/en/web/php_magicquotes>
>>>>
>>>>
>>> Hi Arnold,
>>
>> Just Arno - not Arnold ;-)
>>
>>
>>> That is a lot of overhead on each request.
>>
>> I know - and this is only meant to be a workaround for existing code
>> which can not be easily adopted to handle Magic Quotes and the PHP
>> configuration can not be changed.
>>
>>> And $_REQUEST should be avoided anyway in all situation (in my humble
>>> opinion) for various reasons. But if you use it, it should indeed be
>>> added to your list in your approach.
>>
>> I'm not sure, if it's enough to modify $_GET, $_POST etc. if further
>> parts of a script use $_REQUEST - therefore i added $_REQUEST to be sure.
>>
>>
> I am interested in this, because in general I leave magic quotes on
> because some old code relies on it on some of my sites..

Hi NP,

I feel your pain. I am in the same situation. :-(
(I have an old PHP4.3 machine under my control with magic_quotes on.)


>
>
> Is this comment still true? - its from the PHP manual
>
> "I have discovered that my host doesn't like either of the following
> directives in the .htaccess file:
>
> php_flag magic_quotes_gpc Off
> php_value magic_quotes_gpc Off
>
> However, there is another way to disable this setting even if you don't
> have access to the server configuration - you can put a php.ini file in
> the directory where your scripts are with the directive:
>
> magic_quotes_gpc = Off
>
> However, these does not propogate unlike .htaccess rules, so if you
> launch from a sub-directory, you need the php.ini file in each directory
> you have as script entry points."
>
>
> If so it, gives another option to override server defaults.

I wouldn't bet on that trick to work everywhere.
It seems to me that depends on the way PHP and/or Apache is set up.

Much safer is simply wrap a simple function around $_POST["whatever"] 
that tests for the real situation.
Or use Arno's trick, which is a little heavier on the server because it 
strips more than needed.
The advantage of Arno's approach is of course that you don't have to 
adjust existing code: you can simply enforce magic_quotes or shut them down.

I do prefer a wrapperfunction. That way you have no server dependencies 
in your PHP code.
Well, at least not for magic_quotes that is. ;-)

Regards,
Erwin Moller


-- 
"That which can be asserted without evidence, can be dismissed without 
evidence."
-- Christopher Hitchens

[toc] | [prev] | [next] | [standalone]


#4225

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2012-01-05 15:49 +0000
Message-ID<je4gpn$g52$1@news.albasani.net>
In reply to#4224
Erwin Moller wrote:
> On 1/5/2012 2:36 PM, The Natural Philosopher wrote:
>> Arno Welzel wrote:
>>> Erwin Moller, 2012-01-05 14:08:
>>>
>>>> On 1/4/2012 3:55 PM, Arno Welzel wrote:
>>>>> Michael Joel, 2011-12-29 21:55:
>>>>>
>>>>>> I do not have control of my server (shared server).
>>>>>>
>>>>>> echo get_magic_quotes_gpc(); returns True.
>>>>>> Should I still be cautious and use addslashes/stripslashes in case 
>>>>>> the
>>>>>> hosting company ever decides to change the settings?
>>>>> I assume magic quotes to be disabled and in the past i used the
>>>>> following code fragment to be safe:
>>>>>
>>>>> <http://arnowelzel.de/wiki/en/web/php_magicquotes>
>>>>>
>>>>>
>>>> Hi Arnold,
>>>
>>> Just Arno - not Arnold ;-)
>>>
>>>
>>>> That is a lot of overhead on each request.
>>>
>>> I know - and this is only meant to be a workaround for existing code
>>> which can not be easily adopted to handle Magic Quotes and the PHP
>>> configuration can not be changed.
>>>
>>>> And $_REQUEST should be avoided anyway in all situation (in my humble
>>>> opinion) for various reasons. But if you use it, it should indeed be
>>>> added to your list in your approach.
>>>
>>> I'm not sure, if it's enough to modify $_GET, $_POST etc. if further
>>> parts of a script use $_REQUEST - therefore i added $_REQUEST to be 
>>> sure.
>>>
>>>
>> I am interested in this, because in general I leave magic quotes on
>> because some old code relies on it on some of my sites..
> 
> Hi NP,
> 
> I feel your pain. I am in the same situation. :-(
> (I have an old PHP4.3 machine under my control with magic_quotes on.)
> 
> 
>>
>>
>> Is this comment still true? - its from the PHP manual
>>
>> "I have discovered that my host doesn't like either of the following
>> directives in the .htaccess file:
>>
>> php_flag magic_quotes_gpc Off
>> php_value magic_quotes_gpc Off
>>
>> However, there is another way to disable this setting even if you don't
>> have access to the server configuration - you can put a php.ini file in
>> the directory where your scripts are with the directive:
>>
>> magic_quotes_gpc = Off
>>
>> However, these does not propogate unlike .htaccess rules, so if you
>> launch from a sub-directory, you need the php.ini file in each directory
>> you have as script entry points."
>>
>>
>> If so it, gives another option to override server defaults.
> 
> I wouldn't bet on that trick to work everywhere.
> It seems to me that depends on the way PHP and/or Apache is set up.
> 

well that on my new cheap virtual server is entirely UP TO ME!!

I cannot believe how little it costs, either. <$200 a year (about £160 
uk IIRC)

I am limited on RAM and disk space, and total byte transfers but CPU 
power is  - massive. As is network speed.

Its all RAIDED..

And a quick rsync backs it up on the server here every night..in case.


Best of all with my admin center here on a fixed IP address, I can set 
the firewall to let ME have unlimited access to it.

I actually NFS mount the web sites when I am working on them and edit 
the files directly if I feel lucky. No more FTP uploads.

The cherry on the cake was putting a pass through for its IP address 
into my admin network here and setting up a print queue that prints 
directly to the printer on my desk!

Apart from a slight speed issue saving files, it's like it was a machine 
here in the office.

(except when the power went out last night, it stayed up)

If you have more than a few websites its well worth doing this I feel.


> Much safer is simply wrap a simple function around $_POST["whatever"] 
> that tests for the real situation.
> Or use Arno's trick, which is a little heavier on the server because it 
> strips more than needed.
> The advantage of Arno's approach is of course that you don't have to 
> adjust existing code: you can simply enforce magic_quotes or shut them 
> down.
> 
> I do prefer a wrapperfunction. That way you have no server dependencies 
> in your PHP code.
> Well, at least not for magic_quotes that is. ;-)
> 
> Regards,
> Erwin Moller
> 
> 
IF I was stick with a server setup that meant I had no other choice, I 
would.

My situation is different however. I am looking for the simplest way to 
make it a per site option, and not a global one.

Given its my server to do what I like with..

[toc] | [prev] | [next] | [standalone]


Page 1 of 4  [1] 2 3 4  Next page →

Back to top | Article view | comp.lang.php


csiph-web