Sinisterly
Avoiding SQL Injection With .htaccess - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Design (https://sinister.li/Forum-Design)
+--- Forum: Web Design (https://sinister.li/Forum-Web-Design)
+--- Thread: Avoiding SQL Injection With .htaccess (/Thread-Avoiding-SQL-Injection-With-htaccess)

Pages: 1 2


Avoiding SQL Injection With .htaccess - Tempe - 12-25-2015

merry christmas and new year holiday on the day I will make the thread how to secure a website with .htaccess of sql injection attacks.

[Image: w9eg0n.jpg]

This is an example of a less secure

Code:
RewriteRule ^berita/(.*)/(.*).html$ berita.php?category=$1&item=$2 [NC, QSA]

The second example of this is true


[hide]RewriteRule ^berita/([a-zA-Z0-9-_]+)/([a-zA-Z0-9-_]+).html$ berita.php?berita=$1&item=$2 [NC, QSA][/hide]

in the first instance on a query that category can receive nothing, whereas examples of the latter query is more secure because it has been filtered.


RE: Avoiding SQL Injection With .htaccess - ɘxɘ - 12-25-2015

I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this.


RE: Avoiding SQL Injection With .htaccess - Tempe - 12-28-2015

(12-25-2015, 03:29 PM)hype Wrote: I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this.

how to the best to handle sir?


RE: Avoiding SQL Injection With .htaccess - Sky_mybb_import16331 - 12-28-2015

(12-28-2015, 02:53 AM)Tempe Wrote:
(12-25-2015, 03:29 PM)hype Wrote: I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this.

how to the best to handle sir?

How about using some basic functions for input sanitization?

htmlentities()
htmlspecialchars()
mysql_real_escape_string()


RE: Avoiding SQL Injection With .htaccess - Krados - 12-28-2015

Thanks! Will use it later on my forum.


RE: Avoiding SQL Injection With .htaccess - Sky_mybb_import16331 - 12-28-2015

(12-28-2015, 03:27 AM)Forgotten Wrote: Thanks! Will use it later on my forum.

Once you implement this 'protection' to your forum please PM me the URL so I can hack it, thanks.


RE: Avoiding SQL Injection With .htaccess - ɘxɘ - 12-28-2015

(12-28-2015, 03:14 AM)Sky Wrote:
(12-28-2015, 02:53 AM)Tempe Wrote:
(12-25-2015, 03:29 PM)hype Wrote: I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this.

how to the best to handle sir?

How about using some basic functions for input sanitization?

htmlentities()
htmlspecialchars()
mysql_real_escape_string()

Dang it, @Sky beat me to it.


RE: Avoiding SQL Injection With .htaccess - Para - 12-28-2015

(12-28-2015, 03:14 AM)Sky Wrote:
(12-28-2015, 02:53 AM)Tempe Wrote:
(12-25-2015, 03:29 PM)hype Wrote: I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this.

how to the best to handle sir?

How about using some basic functions for input sanitization?

htmlentities()
htmlspecialchars()
mysql_real_escape_string()

Mysql_real_escape_string() shouldn't really be used anymore it got deprecated somewhere in PHP5 and removed in PHP7.


RE: Avoiding SQL Injection With .htaccess - Sky_mybb_import16331 - 12-28-2015

(12-28-2015, 04:24 PM)Paradigm Wrote:
(12-28-2015, 03:14 AM)Sky Wrote:
(12-28-2015, 02:53 AM)Tempe Wrote:
(12-25-2015, 03:29 PM)hype Wrote: I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this.

how to the best to handle sir?

How about using some basic functions for input sanitization?

htmlentities()
htmlspecialchars()
mysql_real_escape_string()

Mysql_real_escape_string() shouldn't really be used anymore it got deprecated somewhere in PHP5 and removed in PHP7.

But PHP 7 is for gays, I'm sticking with 5.X for now.


RE: Avoiding SQL Injection With .htaccess - Para - 12-28-2015

(12-28-2015, 04:45 PM)Sky Wrote:
(12-28-2015, 04:24 PM)Paradigm Wrote:
(12-28-2015, 03:14 AM)Sky Wrote:
(12-28-2015, 02:53 AM)Tempe Wrote:
(12-25-2015, 03:29 PM)hype Wrote: I still wouldn't rely on this, a hacker can obfuscate the SQL injection to bypass this.

how to the best to handle sir?

How about using some basic functions for input sanitization?

htmlentities()
htmlspecialchars()
mysql_real_escape_string()

Mysql_real_escape_string() shouldn't really be used anymore it got deprecated somewhere in PHP5 and removed in PHP7.

But PHP 7 is for gays, I'm sticking with 5.X for now.
I've gotta be honest I haven't checked PHP7 much yet but the benchmark differences look insane. The only issue for me is they are moving more towards OOP.