sql injection

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • runway27
    Banned
    New Member
    • Sep 2007
    • 54

    #1

    sql injection

    i have implemented a way to avoid sql injection from the php website from this url
    http://in.php.net/mysql_real_escape_string from the "Example #3 A "Best Practice" query" section of this page

    following are the steps i have followed after the form values are submitted to a php file.

    step 1.
    [code=php]
    if(get_magic_qu otes_gpc())
    {
    $username = stripslashes($_ POST["username"]);
    .........
    }

    else
    {
    $username = $_POST["username"];
    .........
    }
    [/code]
    step 2.
    [code=php]
    $conn = mysql_connect($ hostname, $user, $password);
    [/code]
    step 3.
    [code=php]
    $insertquery = sprintf("INSERT INTO table (`username`, ...) VALUES ('%s', ...)", mysql_real_esca pe_string($user name, $conn),

    ...);
    [/code]
    step 4.
    [code=php]
    if(!$conn)
    {
    header("Locatio n: http://website/dberror.html");
    exit;
    }

    else
    {
    mysql_select_db ($database, $conn);

    $insertqueryres ult = mysql_query($in sertquery);


    if(!$insertquer yresult) {
    header("Locatio n: http://website/error.html");
    exit; }

    }
    [/code]
    with the above method i am able to insert values into the table even with if i enter the ' special character which can cause

    problems.

    i have also used a simple sql insert query like
    [code=php]
    $insertquery = "INSERT INTO table(username, ...) VALUES ('$username', ...)";
    [/code]
    when i used this simple insert query and if i entered ' in the form and submitted the form the php file is unable to process

    the information entered because of the ' character and as per the code error.html file is being displayed where as if i use
    [code=php]
    $insertquery = sprintf("INSERT INTO table (`username`, ...) VALUES ('%s', ...)", mysql_real_esca pe_string($user name, $conn),

    ...);
    [/code]
    even if i enter any number of ' characters in more than 1 form field data is being inserted into the table

    a)
    so i am thinking that the steps i have taken from the php site is correct and the right way to avoid sql injection though

    there are several ways to avoid sql injection.

    b)
    for example if i enter data in the form as = abc'''def for name, the data in the table for the name field is being written as

    abc'''def

    based on how i have written the steps to avoid sql injection is this the right way for the data to be stored with '

    characters along with the data example as i mentioned = abc'''def

    please answer the questions a) and b) if there is something else i need to do please suggest what needs to be done exactly

    and at which step.

    any help will be greatly appreciated.

    thanks.
    Last edited by Atli; May 30 '08, 06:29 PM. Reason: Added [code] tags.
  • pbmods
    Recognized Expert Expert
    • Apr 2007
    • 5821

    #2
    Heya, Runway.

    mysql_real_esca pe_string() essentially escapes quotes and comment characters (such as -- and /*) by prepending them with slashes (e.g., "abc'''123" becomes "abc\'\'\'123") .

    Since these characters can be changed (though very rarely are), mysql_real_esca pe_string() is preferred over addslashes() or addcslashes().

    For maximum security and more organized code, you should consider switching to MySQLi and its ability to use prepared statements.

    Comment

    Working...