We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 24719
    • 194 Posts
    hi everyone,

    i’ve been reading about prepared statements and sql attacks, etc, and it turns out that even mysql_escape_string() isn’t enough in some cases (see: http://ilia.ws/archives/103-mysql_real_escape_string-versus-Prepared-Statements.html) to filter submitted data, nor is mysql_real_escape_string. prepared statements are much better, but the old core doesn’t use them.

    so, i was thinking, it’d be safer to compare md5 hashes of data with md5 hashes of submitted data, specifically in the web login processor.

    I think the following is safer than without the md5 hashes (from weblogin.processor.inc.php lines 16-18):

            $sql = "SELECT wu.*
                    FROM $dbase.`".$table_prefix."web_users` wu 
                    WHERE MD5(wu.id)='".md5(mysql_escape_string($id))."'";                
    


    any thoughts? i’d submit this myself to svn, but still haven’t worked it out yet wink (been very busy...)