Table of Contents
Reply content:
Important:
Home Backend Development PHP Tutorial Seeking detailed explanation of mysql_real_escape_string() injection prevention

Seeking detailed explanation of mysql_real_escape_string() injection prevention

Aug 04, 2016 am 09:20 AM
mysql php

mysql_real_escape_string() is regarded as a good alternative to addslashes() and mysql_escape_string(), which can solve wide byte and injection problems, but the official description is unclear:

Seeking detailed explanation of mysql_real_escape_string() injection prevention

mysql_real_escape_string — Escape special characters in strings used in SQL statements, taking into account the current character set of the connection

I really don’t understand this sentence. Considering the current character set of the connection, what does it mean? Can an expert explain it in detail? Thank you!

Reference:
http://php.net/manual/zh/function.mysql-real-escape-string.php
http://www.cnblogs.com/suihui/archive/2012/09/20/2694751. html
http://www.neatstudio.com/show-963-1.shtml

Additional questions: @佢佇俜
1. The added content will not be transferred to mysql, so if ' or 1=1;-- s is injected, the injected content here will not be transferred to mysql in the end. Has it been executed?
Reference: https://segmentfault.com/q/1010000005994443

2.And take into account the current character set of the connectionWhat does it mean? Change the character set of the current connection?

Reply content:

mysql_real_escape_string() is regarded as a good alternative to addslashes() and mysql_escape_string(), which can solve wide byte and injection problems, but the official description is unclear:

Seeking detailed explanation of mysql_real_escape_string() injection prevention

mysql_real_escape_string — Escape special characters in strings used in SQL statements, taking into account the current character set of the connection

I really don’t understand this sentence. Considering the current character set of the connection, what does it mean? Can an expert explain it in detail? Thank you!

Reference:
http://php.net/manual/zh/function.mysql-real-escape-string.php
http://www.cnblogs.com/suihui/archive/2012/09/20/2694751. html
http://www.neatstudio.com/show-963-1.shtml

Additional questions: @佢佇俜
1. The added content will not be transferred to mysql, so if ' or 1=1;-- s is injected, the injected content here will not be transferred to mysql in the end. Has it been executed?
Reference: https://segmentfault.com/q/1010000005994443

2.And take into account the current character set of the connectionWhat does it mean? Change the character set of the current connection?

This is about mysql gbk double-byte injection

For example, user login, assuming your sql statement:
$sql = "select * from user where user_name='$username' and password='$password'";

1 If there is an injection point and there is no escaping. Pass parameter username=' or 1=1;-- s then the sql statement at this time is

$sql = "select * from user where user_name='' or 1=1;-- s ' and password='$password'";

Because -- is a comment character, there is no need to judge whether it has been successfully bypassed later

2 If there is an injection point and special character escapes are used. Then the sql statement at this time is

$sql = "select * from user where user_name='' or 1=1;-- s ' and password='$password'";

Cannot be bypassed

3 At this time, the problem came. An awesome hacker discovered that there is wide byte injection in gbk encoding. At this time, pass username=%df%27 or 1=1;--

The sql statement executed at this time becomes:

$sql = "select * from user where user_name='luck' or 1=1;-- s ' and password='$password'"; Successfully bypassed

How to solve this problem

mysql_real_escape_string — Escape special characters in strings used in SQL statements, taking into account the current character set of the connection

The escaping mechanism of the

mysql_real_escape_string method for SQL statements changes with the change of the character set of the current database connection. For the same SQL statement, the escaped results may not be the same under different character sets.

Important:

The

mysql_real_escape_string method belongs to the mysql extension, which has been marked obsolete since PHP version 5.5.0 and removed since PHP version 7. Please use mysqli or PDO extension for database operations. Please try to use utf8 or utf8mb4 (better) as the database character set.

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

Hot Topics

Java Tutorial
1664
14
PHP Tutorial
1267
29
C# Tutorial
1239
24
MySQL and phpMyAdmin: Core Features and Functions MySQL and phpMyAdmin: Core Features and Functions Apr 22, 2025 am 12:12 AM

MySQL and phpMyAdmin are powerful database management tools. 1) MySQL is used to create databases and tables, and to execute DML and SQL queries. 2) phpMyAdmin provides an intuitive interface for database management, table structure management, data operations and user permission management.

The Compatibility of IIS and PHP: A Deep Dive The Compatibility of IIS and PHP: A Deep Dive Apr 22, 2025 am 12:01 AM

IIS and PHP are compatible and are implemented through FastCGI. 1.IIS forwards the .php file request to the FastCGI module through the configuration file. 2. The FastCGI module starts the PHP process to process requests to improve performance and stability. 3. In actual applications, you need to pay attention to configuration details, error debugging and performance optimization.

Explain the purpose of foreign keys in MySQL. Explain the purpose of foreign keys in MySQL. Apr 25, 2025 am 12:17 AM

In MySQL, the function of foreign keys is to establish the relationship between tables and ensure the consistency and integrity of the data. Foreign keys maintain the effectiveness of data through reference integrity checks and cascading operations. Pay attention to performance optimization and avoid common errors when using them.

Compare and contrast MySQL and MariaDB. Compare and contrast MySQL and MariaDB. Apr 26, 2025 am 12:08 AM

The main difference between MySQL and MariaDB is performance, functionality and license: 1. MySQL is developed by Oracle, and MariaDB is its fork. 2. MariaDB may perform better in high load environments. 3.MariaDB provides more storage engines and functions. 4.MySQL adopts a dual license, and MariaDB is completely open source. The existing infrastructure, performance requirements, functional requirements and license costs should be taken into account when choosing.

SQL vs. MySQL: Clarifying the Relationship Between the Two SQL vs. MySQL: Clarifying the Relationship Between the Two Apr 24, 2025 am 12:02 AM

SQL is a standard language for managing relational databases, while MySQL is a database management system that uses SQL. SQL defines ways to interact with a database, including CRUD operations, while MySQL implements the SQL standard and provides additional features such as stored procedures and triggers.

How does MySQL differ from Oracle? How does MySQL differ from Oracle? Apr 22, 2025 pm 05:57 PM

MySQL is suitable for rapid development and small and medium-sized applications, while Oracle is suitable for large enterprises and high availability needs. 1) MySQL is open source and easy to use, suitable for web applications and small and medium-sized enterprises. 2) Oracle is powerful and suitable for large enterprises and government agencies. 3) MySQL supports a variety of storage engines, and Oracle provides rich enterprise-level functions.

What happens if session_start() is called multiple times? What happens if session_start() is called multiple times? Apr 25, 2025 am 12:06 AM

Multiple calls to session_start() will result in warning messages and possible data overwrites. 1) PHP will issue a warning, prompting that the session has been started. 2) It may cause unexpected overwriting of session data. 3) Use session_status() to check the session status to avoid repeated calls.

MySQL: The Database, phpMyAdmin: The Management Interface MySQL: The Database, phpMyAdmin: The Management Interface Apr 29, 2025 am 12:44 AM

MySQL and phpMyAdmin can be effectively managed through the following steps: 1. Create and delete database: Just click in phpMyAdmin to complete. 2. Manage tables: You can create tables, modify structures, and add indexes. 3. Data operation: Supports inserting, updating, deleting data and executing SQL queries. 4. Import and export data: Supports SQL, CSV, XML and other formats. 5. Optimization and monitoring: Use the OPTIMIZETABLE command to optimize tables and use query analyzers and monitoring tools to solve performance problems.

See all articles