Re: Effectiveness of pg_escape_string at blocking SQL injection attacks

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On Fri, May 27, 2005 at 10:57:16 -0500,
  Ed Finkler <coj@xxxxxxxxxxxxxxxxx> wrote:
> Folks,
> 
> The php mysql api has a function "mysql_real_escape_string" that seems 
> to be able to thwart known SQL injection attacks -- at least the ones of 
> which I and other people I've discussed this with know.  I am curious to 
> know if pg_escape_string is as effective.  If not, what would need to be 
> modified to make it more effective?
> 
> (there is a possibility that I may be able to get a grad student to work 
>  on this at the center, so detailed responses would be appreciated.)

The best advice is to use bind parameters rather than trying to build
SQL strings consisting partly of user input.


[Index of Archives]     [Postgresql General]     [Postgresql Admin]     [PHP Users]     [PHP Home]     [PHP on Windows]     [Kernel Newbies]     [PHP Classes]     [PHP Databases]     [Yosemite Backpacking]     [Postgresql Jobs]

  Powered by Linux