Sinisterly
[NULL] PHP input Sanitization - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Coding (https://sinister.li/Forum-Coding)
+--- Forum: PHP (https://sinister.li/Forum-PHP)
+--- Thread: [NULL] PHP input Sanitization (/Thread-NULL-PHP-input-Sanitization)

Pages: 1 2


RE: [NULL] PHP input Sanitization - Para - 11-25-2015

(11-25-2015, 12:45 PM)zayne Wrote:
(11-25-2015, 09:01 AM)Oxide Wrote:
(11-25-2015, 12:19 AM)zayne Wrote:
(11-24-2015, 01:56 PM)Sky Wrote: Well since you asked me to correct you I guess I can.
Your query is wrong.

Code:
SELECT * FROM posts WHERE user = '' and 1=1--'

When in fact it would be (As you already stated in the thread)

Code:
SELECT * FROM posts WHERE user = '$enteredvalue'

Not quite sure why you moved the payload outside the point of injection.
Yeah what she said ^, and try to avoid using deprecated functions.

I will update this when I get home. I used deprecated php functions to show examples of poor php coding that leaves you open to sql injection.
Yeah I figured. What I meant but didn't state was that developers (or anyone for that matter) shouldn't be using old deprecated functions. In-fact they was released a long time ago (can it be 12-15 years?) which means the API is probably pretty out-dated (or just bad) and that is the main reason they decided to put out a new library of functions with a better API. Secondly, I am sure these deprecated functions will be removed in the near future. When the functions are removed, your vulnerable piece of code will not run correctly. 
What I tried to say is that you could of still demonstrated this with another set of functions which is not deprecated. For example not escaping the concentrating input correctly.

I will post a example in PDO where the statements aren't prepared and therefore are not sanitized. Thanks for the feedback.


RE: [NULL] PHP input Sanitization - Jasper - 11-27-2015

A beginning of a good tutorial. Keep it up.


RE: [NULL] PHP input Sanitization - Austin_mybb_import6214 - 11-28-2015

Good tutorial, I hope to see more! :yus:


RE: [NULL] PHP input Sanitization - Dastil - 11-30-2015

Nice tutorial! I definitely agree that it is important to sanitize input in PHP. PDO is the best approach, I think. Using htmlentities() is important too though.