RE: [NULL] PHP input Sanitization 11-25-2015, 09:37 PM
#11
(11-25-2015, 12:45 PM)zayne Wrote:(11-25-2015, 09:01 AM)Oxide Wrote:Yeah I figured. What I meant but didn't state was that developers (or anyone for that matter) shouldn't be using old deprecated functions. In-fact they was released a long time ago (can it be 12-15 years?) which means the API is probably pretty out-dated (or just bad) and that is the main reason they decided to put out a new library of functions with a better API. Secondly, I am sure these deprecated functions will be removed in the near future. When the functions are removed, your vulnerable piece of code will not run correctly.(11-25-2015, 12:19 AM)zayne Wrote:(11-24-2015, 01:56 PM)Sky Wrote: Well since you asked me to correct you I guess I can.Yeah what she said ^, and try to avoid using deprecated functions.
Your query is wrong.
Code:SELECT * FROM posts WHERE user = '' and 1=1--'
When in fact it would be (As you already stated in the thread)
Code:SELECT * FROM posts WHERE user = '$enteredvalue'
Not quite sure why you moved the payload outside the point of injection.
I will update this when I get home. I used deprecated php functions to show examples of poor php coding that leaves you open to sql injection.
What I tried to say is that you could of still demonstrated this with another set of functions which is not deprecated. For example not escaping the concentrating input correctly.
I will post a example in PDO where the statements aren't prepared and therefore are not sanitized. Thanks for the feedback.
#LeSquad #Satellite





![[+]](https://sinister.li/images/modern/collapse_collapsed.png)
