![]() |
|
[NULL] PHP input Sanitization - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Coding (https://sinister.li/Forum-Coding) +--- Forum: PHP (https://sinister.li/Forum-PHP) +--- Thread: [NULL] PHP input Sanitization (/Thread-NULL-PHP-input-Sanitization) Pages:
1
2
|
[NULL] PHP input Sanitization - Para - 11-22-2015 ![]() I've decided I'm going to be writing some basic PHP tutorials for the community for PHP developers and people who are learning PHP. I in no way claim to know everything about PHP, these are just basic tutorials that should assist new developers. ![]() SQL
SQL Injections are the most common type of attack on a website. An SQL Injection is the process of inserting a malicious SQL query into an application that shouldn't allow the query to be run. The malicious query will then return data that users should not be able to access such as usernames/passwords(hopefully hashes).
A lot of PHP developers still use the deprecated mysql_query PHP function found here. Using this method requires a lot of additional work to sanitise the input of queries. Below is an example of a script that is open to an SQL injection in the most basic form.
PHP Code: <?php
mysql_connect('localhost', 'nulladmin', 'password1');
mysql_select_db('nulldb');
//The value the user enters
$enteredvalue = $_GET['enteredvalue'];
//SQL query running the unsanitized GET value
$sqlquery = mysql_query("SELECT * FROM posts WHERE user = '$enteredvalue'");
?>The issue with the above script is that any input placed into the GET parameter is then placed within the SQL query as the input has not been sanitized. This allows the query open for attackers to add additional SQL into the query to return additional data from the database. This means that when any data put into the GET parameter will be run such as Code: http://nullgroup.dev/script.php?enteredvalue=' and 1=1--Runs the below query on the database Code: SELECT * FROM posts WHERE user = '' and 1=1--'This is the most basic form of an SQL injection. The question is how to sanitise the data being placed in your GET parameter and the simple answer to that is prepared statements. I use PDO for my prepared statements however PHP provides several ways to sanitise data input . PDO and prepared statements used properly can eliminate all threats of an SQL injection. You can find some info about PDO from the PHP website here. A simple explanation of prepared statements is that you write a SQL query and state which values within that query will be from the user input. You then bind the value of the user input to the placeholder in the query and any malicious content placed in the user input is removed. I will not go into a full explanation on how to use PDO and prepared statements as this is not a PDO tutorial however if you are interested on a for a full explanation of PDO check out the PHP website. ![]() XSS
Coming soon..
inb4 @Sky corrects me :hurr: :hurr: RE: [NULL] PHP input Sanitization - II - 11-22-2015 very nice layout man! it´s actually interesting to read
RE: [NULL] PHP input Sanitization - -Wolf- - 11-22-2015 Nice share! Easy and pretty to my eyes too haha RE: [NULL] PHP input Sanitization - Meowie - 11-23-2015 You should give some PDO examples and not just link a PDO doc. If you were gonna do that, you could've just linked some resources and leave it at that. RE: [NULL] PHP input Sanitization - Para - 11-23-2015 (11-23-2015, 09:07 PM)Meowie Wrote: You should give some PDO examples and not just link a PDO doc. I am going to add some examples I just run out of time writing this. RE: [NULL] PHP input Sanitization - Sky_mybb_import16331 - 11-24-2015 Well since you asked me to correct you I guess I can. Your query is wrong. Code: SELECT * FROM posts WHERE user = '' and 1=1--'When in fact it would be (As you already stated in the thread) Code: SELECT * FROM posts WHERE user = '$enteredvalue'Not quite sure why you moved the payload outside the point of injection. RE: [NULL] PHP input Sanitization - Zayne_mybb_import19817 - 11-25-2015 (11-24-2015, 01:56 PM)Sky Wrote: Well since you asked me to correct you I guess I can.Yeah what she said ^, and try to avoid using deprecated functions. RE: [NULL] PHP input Sanitization - Para - 11-25-2015 (11-25-2015, 12:19 AM)zayne Wrote:(11-24-2015, 01:56 PM)Sky Wrote: Well since you asked me to correct you I guess I can.Yeah what she said ^, and try to avoid using deprecated functions. I will update this when I get home. I used deprecated php functions to show examples of poor php coding that leaves you open to sql injection. RE: [NULL] PHP input Sanitization - Zayne_mybb_import19817 - 11-25-2015 (11-25-2015, 09:01 AM)Oxide Wrote:Yeah I figured. What I meant but didn't state was that developers (or anyone for that matter) shouldn't be using old deprecated functions. In-fact they was released a long time ago (can it be 12-15 years?) which means the API is probably pretty out-dated (or just bad) and that is the main reason they decided to put out a new library of functions with a better API. Secondly, I am sure these deprecated functions will be removed in the near future. When the functions are removed, your vulnerable piece of code will not run correctly.(11-25-2015, 12:19 AM)zayne Wrote:(11-24-2015, 01:56 PM)Sky Wrote: Well since you asked me to correct you I guess I can.Yeah what she said ^, and try to avoid using deprecated functions. What I tried to say is that you could of still demonstrated this with another set of functions which is not deprecated. For example not escaping the concentrating input correctly. RE: [NULL] PHP input Sanitization - Skid - 11-25-2015 thanks for this. will be usefull |