Skip to Content
Managing & Using MySQL, 2nd Edition
book

Managing & Using MySQL, 2nd Edition

by Tim King, George Reese, Randy Yarger, Hugh E. Williams
April 2002
Intermediate to advanced
442 pages
16h 37m
English
O'Reilly Media, Inc.
Content preview from Managing & Using MySQL, 2nd Edition

Securing User Data

The clean( ) function in the include file db.inc makes user input secure. The function is shown in Example 11-3, and it takes two parameters: the user $input and the maximum length $maxlength that is expected. It returns the clean user data.

The clean( ) function uses the PHP library string function substr( ) to reduce the length of the $input to its desired maximum. It then uses the PHP library function EscapeShellCmd( ) to insert backslash characters before selected characters—such as semicolons, backslashes, greater-thans, and less-thans—so that their special meanings in Unix shells are nullified or escaped. These two steps are usually sufficient to ensure that users cannot maliciously add extra clauses to SQL queries and cannot manipulate other MySQL library functions.

Warning

Never trust user input or network data.

You should preprocess all user data by escaping special shell characters and ensuring that the data does not exceed a maximum length. A function such as clean( ) in our db.inc include file is useful for this task.

The automatic initialization of variables by the PHP engine also presents a minor security risk. The engine initializes variables in a certain order (defined in PHP’s configuration file php.ini ), which presents the possibility that a variable can be initialized twice, with the second value overwriting the first. For example, by default, the PATH environment variable, which tells the PHP engine where to look for programs, is one of ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

MySQL 8 Cookbook

MySQL 8 Cookbook

Karthik Appigatla
Advanced MySQL 8

Advanced MySQL 8

Eric Vanier, Birju Shah, Tejaswi Malepati
MySQL Stored Procedure Programming

MySQL Stored Procedure Programming

Guy Harrison, Steven Feuerstein
MySQL Reference Manual

MySQL Reference Manual

Michael Widenius, David Axmark, Kaj Arno

Publisher Resources

ISBN: 0596002114Errata Page