Show HN: A “Write Less, Do More” DB Class Based on PDO [PHP]
1–10 of 10 posts
Re: Show HN: A “Write Less, Do More” DB Class Based on PDO [PHP]
#2Re: Show HN: A “Write Less, Do More” DB Class Based on PDO [PHP]
#3Please be aware
Re: Show HN: A “Write Less, Do More” DB Class Based on PDO [PHP]
#4I just want to raise my concern about the security issues the current implementation provides. At a glance the update method provides a simple way to execute arbitrary SQL. Please be aware
https://github.com/resonantcore/lib/blob/7b719907e8954241ff9...
Developer abuse ought to be sufficiently mitigated now. Thanks for saying something :)
Re: Show HN: A “Write Less, Do More” DB Class Based on PDO [PHP]
#5Re: Show HN: A “Write Less, Do More” DB Class Based on PDO [PHP]
#6Where are the tests?
Re: Show HN: A “Write Less, Do More” DB Class Based on PDO [PHP]
#7Where are the tests?
Re: Show HN: A “Write Less, Do More” DB Class Based on PDO [PHP]
#8I just want to raise my concern about the security issues the current implementation provides. At a glance the update method provides a simple way to execute arbitrary SQL. Please be aware
Are you referring to a condition where if you let attackers control the array indices or table name, it's merely sanitized for meta characters? https://github.com/resonantcore/lib/blob/7b719907e8954241ff9... Developer abuse ought to be sufficiently mitigated now. Thanks for saying something :)
You fixed the $i, but what about $table? What about $conditions's keys?
See the problem? And we are just talking about a single method ;-)
Re: Show HN: A “Write Less, Do More” DB Class Based on PDO [PHP]
#9Earlier quoted context omitted.
Are you referring to a condition where if you let attackers control the array indices or table name, it's merely sanitized for meta characters? https://github.com/resonantcore/lib/blob/7b719907e8954241ff9... Developer abuse ought to be sufficiently mitigated now. Thanks for saying something :)
No matter how hard you try. If queries are dynamically created, you (or your lib's user) will most certainly miss a spot were an attacker cloud sneak an offensive query. You fixed the $i, but what about $table? What about $conditions's keys? See the problem? And we are just talking about a single method ;-)
I linked to a single commit.
I probably should have linked to the master branch instead. (Also, I just pushed another update as I wrote this.)
Re: Show HN: A “Write Less, Do More” DB Class Based on PDO [PHP]
#10Earlier quoted context omitted.
Are you referring to a condition where if you let attackers control the array indices or table name, it's merely sanitized for meta characters? https://github.com/resonantcore/lib/blob/7b719907e8954241ff9... Developer abuse ought to be sufficiently mitigated now. Thanks for saying something :)
No matter how hard you try. If queries are dynamically created, you (or your lib's user) will most certainly miss a spot were an attacker cloud sneak an offensive query. You fixed the $i, but what about $table? What about $conditions's keys? See the problem? And we are just talking about a single method ;-)