![]() |
|
Avoiding SQL Injection With .htaccess - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Design (https://sinister.li/Forum-Design) +--- Forum: Web Design (https://sinister.li/Forum-Web-Design) +--- Thread: Avoiding SQL Injection With .htaccess (/Thread-Avoiding-SQL-Injection-With-htaccess) Pages:
1
2
|
Avoiding SQL Injection With .htaccess - Tempe - 12-25-2015 merry christmas and new year holiday on the day I will make the thread how to secure a website with .htaccess of sql injection attacks. ![]() This is an example of a less secure Code: RewriteRule ^berita/(.*)/(.*).html$ berita.php?category=$1&item=$2 [NC, QSA]The second example of this is true [hide]RewriteRule ^berita/([a-zA-Z0-9-_]+)/([a-zA-Z0-9-_]+).html$ berita.php?berita=$1&item=$2 [NC, QSA][/hide] in the first instance on a query that category can receive nothing, whereas examples of the latter query is more secure because it has been filtered. RE: Avoiding SQL Injection With .htaccess - ɘxɘ - 12-25-2015 I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this. RE: Avoiding SQL Injection With .htaccess - Tempe - 12-28-2015 (12-25-2015, 03:29 PM)hype Wrote: I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this. how to the best to handle sir? RE: Avoiding SQL Injection With .htaccess - Sky_mybb_import16331 - 12-28-2015 (12-28-2015, 02:53 AM)Tempe Wrote:(12-25-2015, 03:29 PM)hype Wrote: I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this. How about using some basic functions for input sanitization? htmlentities() htmlspecialchars() mysql_real_escape_string() RE: Avoiding SQL Injection With .htaccess - Krados - 12-28-2015 Thanks! Will use it later on my forum. RE: Avoiding SQL Injection With .htaccess - Sky_mybb_import16331 - 12-28-2015 (12-28-2015, 03:27 AM)Forgotten Wrote: Thanks! Will use it later on my forum. Once you implement this 'protection' to your forum please PM me the URL so I can hack it, thanks. RE: Avoiding SQL Injection With .htaccess - ɘxɘ - 12-28-2015 (12-28-2015, 03:14 AM)Sky Wrote:(12-28-2015, 02:53 AM)Tempe Wrote:(12-25-2015, 03:29 PM)hype Wrote: I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this. Dang it, @Sky beat me to it. RE: Avoiding SQL Injection With .htaccess - Para - 12-28-2015 (12-28-2015, 03:14 AM)Sky Wrote:(12-28-2015, 02:53 AM)Tempe Wrote:(12-25-2015, 03:29 PM)hype Wrote: I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this. Mysql_real_escape_string() shouldn't really be used anymore it got deprecated somewhere in PHP5 and removed in PHP7. RE: Avoiding SQL Injection With .htaccess - Sky_mybb_import16331 - 12-28-2015 (12-28-2015, 04:24 PM)Paradigm Wrote:(12-28-2015, 03:14 AM)Sky Wrote:(12-28-2015, 02:53 AM)Tempe Wrote:(12-25-2015, 03:29 PM)hype Wrote: I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this. But PHP 7 is for gays, I'm sticking with 5.X for now. RE: Avoiding SQL Injection With .htaccess - Para - 12-28-2015 (12-28-2015, 04:45 PM)Sky Wrote:I've gotta be honest I haven't checked PHP7 much yet but the benchmark differences look insane. The only issue for me is they are moving more towards OOP.(12-28-2015, 04:24 PM)Paradigm Wrote:(12-28-2015, 03:14 AM)Sky Wrote:(12-28-2015, 02:53 AM)Tempe Wrote:(12-25-2015, 03:29 PM)hype Wrote: I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this. |