[NULL] PHP input Sanitization 11-22-2015, 10:12 PM
#1
![[Image: XXLMRti.png]](https://i.imgur.com/XXLMRti.png)
I've decided I'm going to be writing some basic PHP tutorials for the community for PHP developers and people who are learning PHP. I in no way claim to know everything about PHP, these are just basic tutorials that should assist new developers.
![[Image: HdYpVGc.png]](http://i.imgur.com/HdYpVGc.png)
SQL
SQL Injections are the most common type of attack on a website. An SQL Injection is the process of inserting a malicious SQL query into an application that shouldn't allow the query to be run. The malicious query will then return data that users should not be able to access such as usernames/passwords(hopefully hashes).
A lot of PHP developers still use the deprecated mysql_query PHP function found here. Using this method requires a lot of additional work to sanitise the input of queries. Below is an example of a script that is open to an SQL injection in the most basic form.
PHP Code:
<?php
mysql_connect('localhost', 'nulladmin', 'password1');
mysql_select_db('nulldb');
//The value the user enters
$enteredvalue = $_GET['enteredvalue'];
//SQL query running the unsanitized GET value
$sqlquery = mysql_query("SELECT * FROM posts WHERE user = '$enteredvalue'");
?>The issue with the above script is that any input placed into the GET parameter is then placed within the SQL query as the input has not been sanitized. This allows the query open for attackers to add additional SQL into the query to return additional data from the database.
This means that when any data put into the GET parameter will be run such as
Code:
http://nullgroup.dev/script.php?enteredvalue=' and 1=1--Runs the below query on the database
Code:
SELECT * FROM posts WHERE user = '' and 1=1--'This is the most basic form of an SQL injection.
The question is how to sanitise the data being placed in your GET parameter and the simple answer to that is prepared statements. I use PDO for my prepared statements however PHP provides several ways to sanitise data input . PDO and prepared statements used properly can eliminate all threats of an SQL injection.
You can find some info about PDO from the PHP website here.
A simple explanation of prepared statements is that you write a SQL query and state which values within that query will be from the user input. You then bind the value of the user input to the placeholder in the query and any malicious content placed in the user input is removed. I will not go into a full explanation on how to use PDO and prepared statements as this is not a PDO tutorial however if you are interested on a for a full explanation of PDO check out the PHP website.
![[Image: HdYpVGc.png]](http://i.imgur.com/HdYpVGc.png)
XSS
Coming soon..
inb4 @Sky corrects me :hurr: :hurr:
#LeSquad #Satellite




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)


![[Image: lQ3OC71.gif]](http://i.imgur.com/lQ3OC71.gif)