Sinisterly
Avoiding SQL Injection With .htaccess - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Design (https://sinister.li/Forum-Design)
+--- Forum: Web Design (https://sinister.li/Forum-Web-Design)
+--- Thread: Avoiding SQL Injection With .htaccess (/Thread-Avoiding-SQL-Injection-With-htaccess)

Pages: 1 2


RE: Avoiding SQL Injection With .htaccess - Sky_mybb_import16331 - 12-28-2015

(12-28-2015, 04:59 PM)Paradigm Wrote:
(12-28-2015, 04:45 PM)Sky Wrote:
(12-28-2015, 04:24 PM)Paradigm Wrote:
(12-28-2015, 03:14 AM)Sky Wrote:
(12-28-2015, 02:53 AM)Tempe Wrote: how to the best to handle sir?

How about using some basic functions for input sanitization?

htmlentities()
htmlspecialchars()
mysql_real_escape_string()

Mysql_real_escape_string() shouldn't really be used anymore it got deprecated somewhere in PHP5 and removed in PHP7.

But PHP 7 is for gays, I'm sticking with 5.X for now.
I've gotta be honest I haven't checked PHP7 much yet but the benchmark differences look insane. The only issue for me is they are moving more towards OOP.

This is exactly why I have little reason to upgrade, they focussed more on the performance than actual functionality.


RE: Avoiding SQL Injection With .htaccess - Jasper - 12-28-2015

Using this is retarded.


RE: Avoiding SQL Injection With .htaccess - Krados - 12-28-2015

(12-28-2015, 02:59 PM)Sky Wrote:
(12-28-2015, 03:27 AM)Forgotten Wrote: Thanks! Will use it later on my forum.

Once you implement this 'protection' to your forum please PM me the URL so I can hack it, thanks.

Alright, I'll make sure to give you access to the database too! <3


RE: Avoiding SQL Injection With .htaccess - thegoldone - 12-30-2015

Hmm, hackers can still bruteforce, but this adds another layer of security.


RE: Avoiding SQL Injection With .htaccess - Jasper - 12-30-2015

(12-30-2015, 01:40 PM)thegoldone Wrote: Hmm, hackers can still bruteforce, but this adds another layer of security.

I wouldn't use this though.


RE: Avoiding SQL Injection With .htaccess - thegoldone - 12-30-2015

Why not though?


RE: Avoiding SQL Injection With .htaccess - Jasper - 12-30-2015

(12-30-2015, 01:48 PM)thegoldone Wrote: Why not though?

Because it's not secure, at all.


RE: Avoiding SQL Injection With .htaccess - Para - 12-30-2015

(12-30-2015, 01:48 PM)thegoldone Wrote: Why not though?
It's pointless, you're just sweeping issues under the carpet rather than resolving them.


RE: Avoiding SQL Injection With .htaccess - thegoldone - 12-30-2015

Really? Hmm.. Okay then


RE: Avoiding SQL Injection With .htaccess - Tempe - 12-31-2015

(12-28-2015, 03:14 AM)Sky Wrote:
(12-28-2015, 02:53 AM)Tempe Wrote:
(12-25-2015, 03:29 PM)hype Wrote: I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this.

how to the best to handle sir?

How about using some basic functions for input sanitization?

htmlentities()
htmlspecialchars()
mysql_real_escape_string()

how the method like this? PHP itself has provided a special method to handle this case, namely

mysql_real_escape or mysql_real_escape_string