Jump to content
php.lv forumi

Kā pārbaudīt drošību?


Devils666

Recommended Posts

Iepazisties lēnā garā ar manis un citu cilvēku sasēņotajiem resursiem:

http://php.lv/f/topic/14308-dokumentipamacibas-par-php-un-web-aplikaciju-drosibu/

Varbūt rodas kāda skaidrība.

 

Paldies, dažas lietas nodereja, bet ja konkrēti

 

if(isset($_GET['id'])) { 
$dabut = addslashes($_GET[id]);

$getuser = mysql_query("SELECT * FROM `blabla` WHERE `id` = '$dabut'");
$usernum = mysql_num_rows($getuser);
if($usernum == 0) 
{ 
echo 'Nepareizs id!'; 
} 

else{
$user = mysql_fetch_array($getuser);
echo "$user[tittle]";

}
}
else{
echo 'Kļūda!'; 
}

 

šajā kodā ko vajadzētu pamainīt? lai viss butu ok ar drošību

Edited by Devils666
Link to comment
Share on other sites

mysql_real_escape() addslashes() vietā. Taču sakarā ar to, ka id ir vesels skaitlis, tad vienkāršāk ar intval() pārveidot un miers.

Indoom jau pateica.

tātad reāli jaizskatās šadi?

 

if (isset($_GET['id']) && is_numeric($_GET['id'])) {
$dabut = intval($_GET[id]);

$getuser = mysql_query("SELECT * FROM `blabla` WHERE `id` = '$dabut'");
$usernum = mysql_num_rows($getuser);

if($usernum == 0) 
{ 
echo 'Nepareizs id!'; 
} 

else{
$user = mysql_fetch_array($getuser);
echo "$user[tittle]";

}


}
else {
echo 'Kļūda!'; 
}

 

un, tad viss butu pareizi?

Edited by Devils666
Link to comment
Share on other sites

es ieteiktu uzmanīties ar is_numeric, jo, ja viņam padot piemēram stringu "2e70", viņš viņu uzskatīs par numeric, bet mysql, ja ieliksi WHERE id=2e70, atrausies ar kļūdu.

 

bet tā tipiskākie drošības caurumi.

1)Neeskeipoti dati db

2)XSS

3)CSRF

Edited by codez
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...