【发布时间】:2009-07-18 01:21:22
【问题描述】:
应该是一个简单的问题,我只是不熟悉 PHP 语法,我想知道以下代码是否可以免受 SQL 注入攻击?:
private function _getAllIngredients($animal = null, $type = null) {
$ingredients = null;
if($animal != null && $type != null) {
$query = 'SELECT id, name, brief_description, description,
food_type, ingredient_type, image, price,
created_on, updated_on
FROM ingredient
WHERE food_type = \'' . $animal . '\'
AND ingredient_type =\'' . $type . '\';';
$rows = $this->query($query);
if(count($rows) > 0) {
等等等等等等
我搜索了一下,似乎注射安全代码看起来与 WHERE food_type = \'' 不同。 $动物。 '\' 在这里使用的语法。
抱歉,我不知道这里使用的是什么版本的 PHP 或 MySQL,或者是否正在使用任何 3rd 方库,任何有专业知识的人都可以提供任何意见吗?
更新
\在语句中的作用是什么?:
WHERE food_type = \'' . $animal . '\'
在我的谷歌搜索中,我发现了很多对 mysql_real_escape_string 的引用...这是防止 SQL 注入和其他恶意行为的功能吗?
类声明是:
class DCIngredient extends SSDataController
那么可以想象mysql_real_escape_string 包含在其中吗?
我应该要求查看 SDataController 的实现吗?
【问题讨论】:
-
\ 转义了 ' 以便它不会终止字符串。如果您键入
'food_type = '' . $animal . ''' 会产生错误。另一种写法是"food_type = '".$animal."'"使用双引号。但是你应该知道双引号也会解析字符串中的变量,而单引号则不会。 -
在回答你的第三个问题时,mysql_real_escape_string 确实转义了字符串以防止 SQL 注入,但你也应该使用准备好的语句。
-
LastName = 'O'Reilley' 怎么样?是转义处理内联单引号吗?这是它的目的吗?
标签: php mysql sql-injection