Thread: sql injection
View Single Post
  #7 (permalink)  
Old 08-10-2004, 02:28 PM
alien3d alien3d is offline
Novice Webmaster
 
Join Date: Nov 2003
Location: malaysia
Posts: 25
Rep Power: 0
alien3d is on a distinguished road
Send a message via MSN to alien3d Send a message via Yahoo to alien3d
Sql injection

cam ni daa
misal page
page.php?sql=<? $sql="update table user administrator='my name' and password"; ?>
kira jika source code ada $sql dia akan automatic guna variable $sql dan itu adalah sql injection.
Untuk mengelakan sql injection kena declare data type macam c tapi php tak support jadi kena declare sendiri
misalnya
$sql=sprintf(%d,$_GET['id]);
Kira id tu nombor guna %d
kalau string
sprintf($s,$_GET['message'];
kalau nak sempoi lagi guna magic quote