Login Register






[NULL] PHP input Sanitization filter_list
Author
Message
RE: [NULL] PHP input Sanitization #11
(11-25-2015, 12:45 PM)zayne Wrote:
(11-25-2015, 09:01 AM)Oxide Wrote:
(11-25-2015, 12:19 AM)zayne Wrote:
(11-24-2015, 01:56 PM)Sky Wrote: Well since you asked me to correct you I guess I can.
Your query is wrong.

Code:
SELECT * FROM posts WHERE user = '' and 1=1--'

When in fact it would be (As you already stated in the thread)

Code:
SELECT * FROM posts WHERE user = '$enteredvalue'

Not quite sure why you moved the payload outside the point of injection.
Yeah what she said ^, and try to avoid using deprecated functions.

I will update this when I get home. I used deprecated php functions to show examples of poor php coding that leaves you open to sql injection.
Yeah I figured. What I meant but didn't state was that developers (or anyone for that matter) shouldn't be using old deprecated functions. In-fact they was released a long time ago (can it be 12-15 years?) which means the API is probably pretty out-dated (or just bad) and that is the main reason they decided to put out a new library of functions with a better API. Secondly, I am sure these deprecated functions will be removed in the near future. When the functions are removed, your vulnerable piece of code will not run correctly. 
What I tried to say is that you could of still demonstrated this with another set of functions which is not deprecated. For example not escaping the concentrating input correctly.

I will post a example in PDO where the statements aren't prepared and therefore are not sanitized. Thanks for the feedback.
#LeSquad #Satellite

Reply

RE: [NULL] PHP input Sanitization #12
A beginning of a good tutorial. Keep it up.

Reply

RE: [NULL] PHP input Sanitization #13
Good tutorial, I hope to see more! :yus:

Reply

RE: [NULL] PHP input Sanitization #14
Nice tutorial! I definitely agree that it is important to sanitize input in PHP. PDO is the best approach, I think. Using htmlentities() is important too though.

Reply