Bugtraq mailing list archives
Intresting case of SQL Injection
From: Sys Sec <syssec () sysigsa com>
Date: Fri, 5 Dec 2003 07:45:48 +0100
IMPORTANT INFORMATION FOR ALL DEVELOPERS OF PHP. I recommend that never leave to insert special characters in input box. Normally in Input Box only is necessary numeric or alphanumeric data For solution this SQL Injection you can use these functions: ctype_alnum -- Check for alphanumeric character(s) ctype_alpha -- Check for alphabetic character(s) ctype_cntrl -- Check for control character(s) ctype_digit -- Check for numeric character(s) ctype_graph -- Check for any printable character(s) except space ctype_lower -- Check for lowercase character(s) ctype_print -- Check for printable character(s) ctype_punct -- Check for any printable character which is not whitespace or an alphanumeric character ctype_space -- Check for whitespace character(s) ctype_upper -- Check for uppercase character(s) ctype_xdigit -- Check for character(s) representing a hexadecimal digit Normally you verify data with Javascript in Client but you must verify data in file that receive POST Form. In the file that receive the POST data you can use these functions. ADDITIONAL INFO: http://es2.php.net/manual/en/ref.ctype.php For use these functions you must discomment library in php.ini file: ;Windows Extensions extension=php_ctype.dll Javier Morueco
Current thread:
- Intresting case of SQL Injection Martin Sarsale (runa@sytes) (Dec 04)
- Re: Intresting case of SQL Injection Markus Fischer (Dec 05)
- <Possible follow-ups>
- Intresting case of SQL Injection Sys Sec (Dec 05)
- Re: Intresting case of SQL Injection Nick FitzGerald (Dec 05)
- RE: Intresting case of SQL Injection Scovetta, Michael V (Dec 05)
- Re: Intresting case of SQL Injection Florian Weimer (Dec 05)
