Re: SQL injection

Поиск
Список
Период
Сортировка
От Yonatan Ben-Nes
Тема Re: SQL injection
Дата
Msg-id 436A006A.3040709@canaan.co.il
обсуждение исходный текст
Ответ на Re: SQL injection  (Hannes Dorbath <light@theendofthetunnel.de>)
Список pgsql-general
Hannes Dorbath wrote:
> On 03.11.2005 04:12, Alex Turner wrote:
>
>> I would have to say that for security purposes - I would want magic
>> quotes _on_ rather than off for the whole reasons of SQL Injection
>> that we already talked about.
>
>
> magic_quotes is evil and does if anything only prevent the simplest
> cases of SQL injections. Keep it turned off. Use
> http://php.net/pg_query_params exclusively to build secure queries..
>
>

The problem with pg_query_params is that you will be forced to use an RC
version of PHP.... I don't know about you but I think that for
production sites I prefer to use the final versions.

I think that prepared statements is the best solution here even if its
encumbering everything alittle...

В списке pgsql-general по дате отправления:

Предыдущее
От: Sim Zacks
Дата:
Сообщение: Re: left join a parenthesised inner join group
Следующее
От: David Gagnon
Дата:
Сообщение: Re: Problem with array in plpgsql function .. please help