Login Register






Avoiding SQL Injection With .htaccess filter_list
Author
Message
RE: Avoiding SQL Injection With .htaccess #11
(12-28-2015, 04:59 PM)Paradigm Wrote:
(12-28-2015, 04:45 PM)Sky Wrote:
(12-28-2015, 04:24 PM)Paradigm Wrote:
(12-28-2015, 03:14 AM)Sky Wrote:
(12-28-2015, 02:53 AM)Tempe Wrote: how to the best to handle sir?

How about using some basic functions for input sanitization?

htmlentities()
htmlspecialchars()
mysql_real_escape_string()

Mysql_real_escape_string() shouldn't really be used anymore it got deprecated somewhere in PHP5 and removed in PHP7.

But PHP 7 is for gays, I'm sticking with 5.X for now.
I've gotta be honest I haven't checked PHP7 much yet but the benchmark differences look insane. The only issue for me is they are moving more towards OOP.

This is exactly why I have little reason to upgrade, they focussed more on the performance than actual functionality.

Reply

RE: Avoiding SQL Injection With .htaccess #12
Using this is retarded.

Reply

RE: Avoiding SQL Injection With .htaccess #13
(12-28-2015, 02:59 PM)Sky Wrote:
(12-28-2015, 03:27 AM)Forgotten Wrote: Thanks! Will use it later on my forum.

Once you implement this 'protection' to your forum please PM me the URL so I can hack it, thanks.

Alright, I'll make sure to give you access to the database too! <3
[Image: opligitorygmailcom.gif]

Reply

RE: Avoiding SQL Injection With .htaccess #14
Hmm, hackers can still bruteforce, but this adds another layer of security.

Reply

RE: Avoiding SQL Injection With .htaccess #15
(12-30-2015, 01:40 PM)thegoldone Wrote: Hmm, hackers can still bruteforce, but this adds another layer of security.

I wouldn't use this though.

Reply

RE: Avoiding SQL Injection With .htaccess #16
Why not though?

Reply

RE: Avoiding SQL Injection With .htaccess #17
(12-30-2015, 01:48 PM)thegoldone Wrote: Why not though?

Because it's not secure, at all.

Reply

RE: Avoiding SQL Injection With .htaccess #18
(12-30-2015, 01:48 PM)thegoldone Wrote: Why not though?
It's pointless, you're just sweeping issues under the carpet rather than resolving them.
#LeSquad #Satellite

Reply

RE: Avoiding SQL Injection With .htaccess #19
Really? Hmm.. Okay then

Reply

RE: Avoiding SQL Injection With .htaccess #20
(12-28-2015, 03:14 AM)Sky Wrote:
(12-28-2015, 02:53 AM)Tempe Wrote:
(12-25-2015, 03:29 PM)hype Wrote: I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this.

how to the best to handle sir?

How about using some basic functions for input sanitization?

htmlentities()
htmlspecialchars()
mysql_real_escape_string()

how the method like this? PHP itself has provided a special method to handle this case, namely

mysql_real_escape or mysql_real_escape_string
[Image: roronoa-zoro-eye-hd.jpg?w=620]

Reply