Why cannot this method prevent SQL injection?

Source: Internet
Author: User
Why cannot this method prevent SQL injection? First of all, I don't know if MySQL can add single quotation marks for all types of data. I just tried to add single quotation marks around the integer.
If it is true that all types of data can be enclosed in single quotes, a single quotation mark will be added to any data when a MySQL statement is generated, use mysql_escape_string to escape all special characters in the received characters. In this way, the received string is completely "restricted" between single quotes.

However, it seems that the conversion and normal strings in strings similar to the like clause are different once and for all. In addition, if any update in the AMP involves escaping, problems may occur. Are there solutions to these two problems once and for all? Is there any other problem?


Reply to discussion (solution)

The conversion and normal strings in the strings after the like clause seem to be different.
Why?

Both MySQL and pdo provide data binding.
Manual escape is not required when data binding is used.

The conversion and normal strings in the strings after the like clause seem to be different.
Why?

Both MySQL and pdo provide data binding.
Manual escape is not required when data binding is used.
The backslash in like seems to be \\\.

Don't come up with an instance.

Don't come up with an instance.
It seems that it is related to PHP and cannot be interviewed directly in the command line. It is completely normal in the command line. In addition, three backslashes are required in phpmyadmin.


Don't come up with an instance.
It seems that it is related to PHP and cannot be interviewed directly in the command line. It is completely normal in the command line. In addition, three backslashes are required in phpmyadmin.
I just typed the backslash into a diagonal line, and I can try it out in the command line.

mysql> use testDatabase changedmysql> create table backlash (id int, value char(20));Query OK, 0 rows affected (0.00 sec)mysql> insert into backlash(id, value) values(1,'\\');Query OK, 1 row affected (0.00 sec)mysql> select * from backlash where value='\\';+------+-------+| id   | value |+------+-------+|    1 | \     |+------+-------+1 row in set (0.00 sec)mysql> select * from backlash where value like '%\\%';Empty set (0.00 sec)mysql> select * from backlash where value like '%\\\%';+------+-------+| id   | value |+------+-------+|    1 | \     |+------+-------+1 row in set (0.00 sec)mysql>

Don't come up with an instance.
To use PHP, add six backslashes:

 ';$result=mysql_query($sql, $conn);$row=mysql_fetch_row($result);echo $row[0];echo '
';?>

In my previous work, I only obtained the backslash through get, so we can simply use three. Confused.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.