Login Register






[NULL] PHP input Sanitization filter_list
Author
Message
RE: [NULL] PHP input Sanitization #9
(11-25-2015, 09:01 AM)Oxide Wrote:
(11-25-2015, 12:19 AM)zayne Wrote:
(11-24-2015, 01:56 PM)Sky Wrote: Well since you asked me to correct you I guess I can.
Your query is wrong.

Code:
SELECT * FROM posts WHERE user = '' and 1=1--'

When in fact it would be (As you already stated in the thread)

Code:
SELECT * FROM posts WHERE user = '$enteredvalue'

Not quite sure why you moved the payload outside the point of injection.
Yeah what she said ^, and try to avoid using deprecated functions.

I will update this when I get home. I used deprecated php functions to show examples of poor php coding that leaves you open to sql injection.
Yeah I figured. What I meant but didn't state was that developers (or anyone for that matter) shouldn't be using old deprecated functions. In-fact they was released a long time ago (can it be 12-15 years?) which means the API is probably pretty out-dated (or just bad) and that is the main reason they decided to put out a new library of functions with a better API. Secondly, I am sure these deprecated functions will be removed in the near future. When the functions are removed, your vulnerable piece of code will not run correctly. 
What I tried to say is that you could of still demonstrated this with another set of functions which is not deprecated. For example not escaping the concentrating input correctly.

Reply





Messages In This Thread
[NULL] PHP input Sanitization - by Para - 11-22-2015, 10:12 PM