Blackout Posted February 9, 2006 Report Share Posted February 9, 2006 Kāds nevar lūdzu apskaidrot kā strādā mysql injekcija un kā viņu apgriezt? Link to comment Share on other sites More sharing options...
bubu Posted February 9, 2006 Report Share Posted February 9, 2006 http://php.lv/f/index.php?showtopic=2935 (SQL injekcijas) Link to comment Share on other sites More sharing options...
Blackout Posted February 9, 2006 Author Report Share Posted February 9, 2006 Jā, bet es tur īsti neiebraucu, pārlasīju. Es nesaprotu jebkurā laukā ierakstot mysql_query vai kko tādu var sataisīt sūdus? ar ereg_replace uz formām var aizsargāt? Link to comment Share on other sites More sharing options...
v3rb0 Posted February 9, 2006 Report Share Posted February 9, 2006 - visu saņemto no usera pārbaudīt vai ir tas ko gaidīji - sql'ā uzmanīgi ar pēdiņam. un būsi diezgan pasargāts no injekcijām. Link to comment Share on other sites More sharing options...
Blackout Posted February 9, 2006 Author Report Share Posted February 9, 2006 v3rb0, bubu paldies. es iešu gulēt. Rītdien uzrakstīšu, pārāk vēls lai turpinātu diskusiju. Link to comment Share on other sites More sharing options...
Ugga Posted February 9, 2006 Report Share Posted February 9, 2006 Kodētājam tikai tagad sākas darbs. :) Link to comment Share on other sites More sharing options...
Blackout Posted February 10, 2006 Author Report Share Posted February 10, 2006 Ugga :) man vnk. skola :). Tātad lai pilnībā aizbloķētu SQL INJECTION man vaig aizliegt simbolus iznemot A-Z a-z 0-1 ? :) Kā īsti tas sql injection strādā? Pie parastas reģistrācijas ir vērts likt kādu pārbaudi? Vai pie komentu likšanas utt arī? Nu reģistrāciju apgriezu. tagad login apgriezīšu. Link to comment Share on other sites More sharing options...
Blackout Posted February 10, 2006 Author Report Share Posted February 10, 2006 Paprasiju citur: man ieteica apm tādu variantu: mysql_query("insert into lol values( '".mysql_escape_string($_POST['lol'])."')"); Link to comment Share on other sites More sharing options...
Kristabs Posted February 11, 2006 Report Share Posted February 11, 2006 Es lietoju: insert into lol values( '".addslashes($_POST['lol'])."') - man liekas, ka pilniibaa pietiek Link to comment Share on other sites More sharing options...
Blackout Posted February 12, 2006 Author Report Share Posted February 12, 2006 addslashes ir tas pats mysql_escape_string ja? :) Link to comment Share on other sites More sharing options...
bubu Posted February 12, 2006 Report Share Posted February 12, 2006 Nē, bet darbojas pēc līdzīgiem principiem (manuālī visu var izlasīt). Link to comment Share on other sites More sharing options...
Blackout Posted February 13, 2006 Author Report Share Posted February 13, 2006 Paldies. bet iznākums kā es sapraut tikuntā viens un tas pats. Link to comment Share on other sites More sharing options...
Recommended Posts