Filtering SQL Injections.

Skilled Illusionist
Joined
Dec 25, 2009
Messages
370
Reaction score
234
Ohai,
Cuz some people have problems with SQL Injections. I have something that filters all the $_GET and $_POST.

Here u go:
PHP:
foreach($_GET as $key => $value)
  {
    $_GET[$key]= addslashes_mssql($value);
  }
  foreach($_POST as $key => $value)
  {
    $_POST[$key]= addslashes_mssql($value);
  }

Put it in a global page, or something that every page include.

Cya.
 
Last edited:
mysql_real_escape_string only works if there's a MySQL connection to a database.
php.net said:
A MySQL connection is required before using mysql_real_escape_string() otherwise an error of level E_WARNING is generated, and FALSE is returned. If link_identifier isn't defined, the last MySQL connection is used.

And what does the function addslashes_mssql do? Is it the same as addslashes? I never heard of that function and can't find it at php.net either. :o

If it's the same as the normal addslashes, then it can be bypassed.
 
PHP:
$query = "Update Account SET Name = ? WHERE UserID = ?";
$params = array('"DROP TABLE Login', "Test");
sqlsrv_query($query, $params);
zp2X - Filtering SQL Injections. - RaGEZONE Forums

PHP:
$query = "Update Account SET Name = ? WHERE UserID = ?";
$params = array("'DROP TABLE Login", "Test");
sqlsrv_query($query, $params);
HRdIZ - Filtering SQL Injections. - RaGEZONE Forums
 
mysql_real_escape_string only works if there's a MySQL connection to a database.


And what does the function addslashes_mssql do? Is it the same as addslashes? I never heard of that function and can't find it at php.net either. :o

If it's the same as the normal addslashes, then it can be bypassed.

I thought so, until fucking Cosmos told me it's just a filter, my bad.
 
I thought so, until fucking Cosmos told me it's just a filter, my bad.
Meh, had to do with the fact that I was porting the SQL class I was using for my site(Originally it was using MySQL, now MSSQL, used to be for 2 different games altogether). Anyway, it is your fault for quoting me without verifying, so shut your mouth.
 
Why should you use

foreach($_GET as $key => $value)
{
$_GET[$key]= addslashes_mssql($value);
}
foreach($_POST as $key => $value)
{
$_POST[$key]= addslashes_mssql($value);
}

Make a function? and use more then only addslashes -_-!
 
Back