Beefy Boxes and Bandwidth Generously Provided by pair Networks
Syntactic Confectionery Delight
 
PerlMonks  

Re^3: Hacker Proofing My Script

by awohld (Hermit)
on Oct 04, 2004 at 21:02 UTC ( #396386=note: print w/replies, xml ) Need Help??


in reply to Re^2: Hacker Proofing My Script
in thread Hacker Proofing My Script

jZed -

So you say if my database, which is mySQL 3.22.32, supports placeholders, then I don't have to worry if the DBD supports or emulates them?

Thanks
Adam

Replies are listed 'Best First'.
Re^4: Hacker Proofing My Script
by jZed (Prior) on Oct 04, 2004 at 21:13 UTC
    I don't know a heck of a lot about MySQL, but according to gmax's excellent New twist for DBD::mysql, DBD::mysql currently does emulate placeholders but in such a way as to preserve security. I'd suggest reading his node for further details.
      It doesn't seem to be totally secure:
      As for LIMIT ?,?. The reason why it was not supported since 2.9002 is that it allowed for sql injection attacks, and it is not trivial to fix, in fact, I *just* scanned over Patrick's code and found a bug in the LIMIT handling code
      as can be read in Re: New twist for DBD::mysql.

      CountZero

      "If you have four groups working on a compiler, you'll get a 4-pass compiler." - Conway's Law

Log In?
Username:
Password:

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://396386]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this? | Other CB clients
Other Users?
Others cooling their heels in the Monastery: (8)
As of 2020-01-22 16:39 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?
    Notices?