Problem Solution Discussion Using Web Input to Construct Queries
18.8 Using Web Input to Construct Queries
18.8.1 Problem
I nput obt ained over t he Web cannot be t rust ed and should not be placed int o a query wit hout t aking t he proper precaut ions.18.8.2 Solution
Sanit ize dat a values by using placeholders or a quot ing funct ion.18.8.3 Discussion
Aft er youve ext ract ed input param et er values and checked t hem t o m ake sure t heyre valid, youre ready t o use t hem t o const ruct a query. This is act ually t he easy part , t hough it s necessary t o t ake t he proper precaut ions t o avoid m aking a m ist ake t hat youll regret . First , let s consider what can go wrong, t hen see how t o prevent t he problem . Suppose you have a search form cont aining a keyword field t hat act s as a front end t o a sim ple search engine. When a user subm it s a keyword, you int end t o use it t o find m at ching records in a t able by const ruct ing a query like t his: SELECT FROM mytbl WHERE keyword = keyword_val Here, keyword_val represent s t he value ent ered by t he user. I f t he value is som et hing like eggplant , t he r esult ing query is: SELECT FROM mytbl WHERE keyword = eggplant The query ret urns all eggplant - m at ching records, presum ably generat ing a sm all result set . But suppose t he user is t ricky and t ries t o subvert your script by ent ering t he following value: eggplant OR x=x I n t his case, t he query becom es: SELECT FROM mytbl WHERE keyword = eggplant OR x=x That query m at ches every record in t he t able I f t he t able is quit e large, t he input effect ively becom es a form of denial- of- service at t ack, because it causes your syst em t o devot e resources away from legit im at e request s int o doing useless work. Likely result s are: • Ext ra load on t he MySQL server • Out - of-m em ory problem s in your script as it t ries t o digest t he result set received from MySQL • Ext ra net work bandwidt h consum pt ion as t he script sends t he result s t o t he client I f your script generat es a DELETE st at em ent , t he consequences of t his kind of subversion can be m uch w orse—your script m ight issue a query t hat em pt ies a t able com plet ely, when you int ended t o allow it t o delet e only a single record at a t im e. The im plicat ion is t hat providing a web int erface t o your dat abase opens you up t o cert ain form s of at t ack. However, you can prevent t his kind of problem by m eans of a sim ple precaut ion t hat you should already be following: dont put dat a values lit erally int o query st rings. Use placeholders or an encoding funct ion inst ead. For exam ple, in Perl you can handle an input param et er like t his using placeholders: keyword = param keyword; sth = dbh-prepare SELECT FROM mytbl WHERE keyword = ?; sth-execute keyword; ... fetch result set ... Or like t his using quote : keyword = param keyword; keyword = dbh-quote keyword; sth = dbh-prepare SELECT FROM mytbl WHERE keyword = keyword; sth-execute ; ... fetch result set ... Eit her way, if t he user ent ers t he subversive value, t he query becom es: SELECT FROM mytbl WHERE keyword = eggplant\ OR \x\=\x The input is rendered harm less, and t he result is t hat t he query will m at ch no records rat her t han all records—definit ely a m ore suit able response t o som eone whos t rying t o break your script . Placeholder and quot ing t echniques for PHP, Pyt hon, and Java are sim ilar, and have been discussed in Recipe 2.7 and Recipe 2.8 . For JSP pages writ t en using t he JSTL t ag library, you can quot e input param et er values using placeholders and t he sql:param t ag Recipe 16.4 . For exam ple, t o use t he value of a form param et er nam ed keyword in a SELECT st at em ent , do t his: sql:query var=rs dataSource={conn} SELECT FROM mytbl WHERE keyword = ? sql:param value={param[keyword]} sql:query Placeholders and encoding funct ions apply only t o SQL dat a values. One issue not addressed by t hem is how t o handle web input used for ot her kinds of query elem ent s such as t he nam es of dat abases, t ables, and colum ns. I f you int end t o insert such values int o a query, you m ust insert t hem lit erally, which m eans you should check t hem first . For exam ple, if you const ruct a query such as t he following, you should verify t hat tbl_name cont ains a reasonable value: SELECT FROM tbl_name; But what does reasonable m ean? I f you dont have t ables cont aining st range charact ers in t heir nam es, it m ay be sufficient t o m ake sure t hat tbl_name cont ains only alphanum eric charact ers or underscores. An alt ernat ive is t o issue a SHOW TABLES quer y t o m ake sure t hat t he t able nam e in quest ion is in t he dat abase. This is m ore foolproof, at t he cost of an addit ional query. Anot her issue not covered by placeholder t echniques involves a quest ion of int erpret at ion: if a form field is opt ional, what should you st ore in t he dat abase if t he user leaves t he field em pt y? Perhaps t he value represent s an em pt y st ring—or perhaps it should be int erpret ed as NULL . One way t o resolve t his quest ion is t o consult t he colum n m et adat a. I f t he colum n can cont ain NULL values, t hen int erpret an em pt y field as NULL . Ot herw ise, t ake an em pt y field t o m ean an em pt y st ring. Try to Break Your Scripts The discussion in t his sect ion has been phrased in t erm s of guarding against ot her users from at t acking your script s. But it s not a bad idea t o put yourself in t he place of an at t acker and adopt t he m indset , How can I break t his applicat ion? That is, consider whet her t here is som e input you can subm it t o it t hat t he applicat ion wont handle, and t hat will cause it t o generat e a m alform ed query? I f you can cause it t o m isbehave, so can ot her people, eit her deliberat ely or accident ally. Be wary of bad input , and writ e your applicat ions accordingly. I t s bet t er t o be prepared t han t o j ust hope.18.8.4 See Also
Parts
» O'Reilly-MySQL.Cookbook.eBook-iNTENSiTY. 4810KB Mar 29 2010 05:03:43 AM
» Introduction Using the mysql Client Program
» Problem Solution Discussion Setting Up a MySQL User Account
» Problem Solution Discussion Starting and Terminating mysql
» Problem Solution Discussion Specifying Connection Parameters by Using Option Files
» Problem Solution Discussion Mixing Command-Line and Option File Parameters
» Problem Solution Discussion What to Do if mysql Cannot Be Found
» Problem Solution Discussion Setting Environment Variables
» Problem Solution Discussion Repeating and Editing Queries
» Problem Solution Discussion Preventing Query Output from Scrolling off the Screen
» Problem Solution Discussion Specifying Arbitrary Output Column Delimiters
» Problem Solution Discussion Logging Interactive mysql Sessions
» Discussion Using mysql as a Calculator
» Writing Shell Scripts Under Unix
» Writing Shell Scripts Under Windows
» MySQL Client Application Programming Interfaces
» Perl Connecting to the MySQL Server, Selecting a Database, and Disconnecting
» PHP Connecting to the MySQL Server, Selecting a Database, and Disconnecting
» Python Connecting to the MySQL Server, Selecting a Database, and Disconnecting
» Java Connecting to the MySQL Server, Selecting a Database, and Disconnecting
» Problem Solution Discussion Checking for Errors
» Python Java Checking for Errors
» Problem Solution Discussion Writing Library Files
» Python Writing Library Files
» SQL Statement Categories Issuing Queries and Retrieving Results
» Perl Issuing Queries and Retrieving Results
» Python Issuing Queries and Retrieving Results
» Java Issuing Queries and Retrieving Results
» Problem Solution Discussion Moving Around Within a Result Set
» Problem Solution Discussion Using Prepared Statements and Placeholders in Queries
» Perl Using Prepared Statements and Placeholders in Queries
» PHP Python Java Using Prepared Statements and Placeholders in Queries
» Problem Solution Discussion Including Special Characters and NULL Values in Queries
» Perl Including Special Characters and NULL Values in Queries
» PHP Including Special Characters and NULL Values in Queries
» Python Java Including Special Characters and NULL Values in Queries
» PHP Python Java Handling NULL Values in Result Sets
» Problem Solution Discussion Writing an Object-Oriented MySQL Interface for PHP
» Class Overview Writing an Object-Oriented MySQL Interface for PHP
» Connecting and Disconnecting Writing an Object-Oriented MySQL Interface for PHP
» Error Handling Issuing Queries and Processing the Results
» Quoting and Placeholder Support
» Problem Solution Discussion Ways of Obtaining Connection Parameters
» Getting Parameters from the Command Line
» Getting Parameters from Option Files
» Conclusion and Words of Advice
» Problem Solution Discussion Avoiding Output Column Order Problems When Writing Programs
» Problem Solution Discussion Using Column Aliases to Make Programs Easier to Write
» Problem Solution Discussion Selecting a Result Set into an Existing Table
» Problem Solution Discussion Creating a Destination Table on the Fly from a Result Set
» Problem Solution Discussion Moving Records Between Tables Safely
» Problem Solution Discussion Cloning a Table Exactly
» Problem Solution Discussion Generating Unique Table Names
» Problem Solution Discussion Using TIMESTAMP Values
» Problem Solution Discussion Using ORDER BY to Sort Query Results
» Solution Discussion Working with Per-Group and Overall Summary Values Simultaneously
» Problem Solution Discussion Changing a Column Definition or Name
» Problem Solution Discussion Changing a Table Type
» Problem Solution Discussion Adding Indexes
» Introduction Obtaining and Using Metadata
» Problem Solution Discussion Perl PHP
» Problem Solution Discussion Perl
» PHP Obtaining Result Set Metadata
» Python Obtaining Result Set Metadata
» Java Obtaining Result Set Metadata
» Using Result Set Metadata to Get Table Structure
» Problem Solution Discussion Database-Independent Methods of Obtaining Table Information
» Problem Solution Discussion Displaying Column Lists Interactive Record Editing
» Mapping Column Types onto Web Page Elements Adding Elements to ENUM or SET Column Definitions
» Selecting All Except Certain Columns
» Problem Solution Discussion Listing Tables and Databases
» Problem Solution Writing Applications That Adapt to the MySQL Server Version
» Discussion Writing Applications That Adapt to the MySQL Server Version
» Problem Solution Discussion Determining Which Table Types the Server Supports
» General Import and Export Issues
» Problem Solution Discussion Importing Data with LOAD DATA and mysqlimport
» Problem Solution Discussion Specifying the Datafile Location
» Problem Solution Discussion Specifying the Datafile Format
» Problem Solution Discussion Dealing with Quotes and Special Characters
» Problem Solution Discussion Handling Duplicate Index Values
» Problem Solution Discussion Getting LOAD DATA to Cough Up More Information
» Problem Solution Discussion Dont Assume LOAD DATA Knows More than It Does
» Problem Solution Discussion Skipping Datafile Columns
» Problem Solution Discussion Exporting Query Results from MySQL
» Using the mysql Client to Export Data
» Problem Solution Discussion Exporting Tables as Raw Data
» Problem Solution Discussion Exporting Table Contents or Definitions in SQL Format
» Problem Solution Discussion Copying Tables or Databases to Another Server
» Problem Solution Discussion Writing Your Own Export Programs
» Problem Solution Discussion Converting Datafiles from One Format to Another
» Problem Solution Discussion Extracting and Rearranging Datafile Columns
» Problem Solution Discussion Validating and Transforming Data
» Writing an Input-Processing Loop Putting Common Tests in Libraries
» Problem Solution Discussion Validation by Pattern Matching
» Problem Solution Discussion Using Patterns to Match Numeric Values
» Problem Solution Discussion Using Patterns to Match Dates or Times
» See Also Using Patterns to Match Dates or Times
» Problem Solution Discussion Using Patterns to Match Email Addresses and URLs
» Problem Solution Discussion Validation Using Table Metadata
» Problem Solution Discussion Issue Individual Queries Construct a Hash from the Entire Lookup Table
» Use a Hash as a Cache of Already-Seen Lookup Values
» Problem Solution Discussion Converting Two-Digit Year Values to Four-Digit Form
» Problem Solution Discussion Performing Validity Checking on Date or Time Subparts
» Problem Solution Discussion Writing Date-Processing Utilities
» Problem Solution Discussion Performing Date Conversion Using SQL
» Problem Solution Discussion Guessing Table Structure from a Datafile
» Problem Solution Discussion A LOAD DATA Diagnostic Utility
» Problem Solution Discussion Exchanging Data Between MySQL and Microsoft Access
» Problem Solution Discussion Exchanging Data Between MySQL and Microsoft Excel
» Problem Solution Discussion Exchanging Data Between MySQL and FileMaker Pro
» Problem Solution Discussion Importing XML into MySQL
» Epilog Importing and Exporting Data
» Introduction Generating and Using Sequences
» Problem Solution Discussion Using AUTO_INCREMENT To Set Up a Sequence Column
» Problem Solution Discussion Choosing the Type for a Sequence Column
» Problem Solution Discussion Ensuring That Rows Are Renumbered in a Particular Order
» Problem Solution Discussion Managing Multiple Simultaneous AUTO_INCREMENT Values
» Problem Solution Discussion Using AUTO_INCREMENT Values to Relate Tables
» Problem Solution Discussion Generating Repeating Sequences
» Problem Solution Discussion See Also
» Performing a Related-Table Update Using Table Replacement
» Performing a Related-Table Update by Writing a Program
» Performing a Multiple-Table Delete by Writing a Program
» Problem Solution Discussion Dealing with Duplicates at Record-Creation Time
» Problem Solution Discussion Using Transactions in Perl Programs
» Problem Solution Discussion Using Transactions in Java Programs
» Problem Solution Discussion Using Alternatives to Transactions
» Grouping Statements Using Locks
» Rewriting Queries to Avoid Transactions
» Introduction Introduction to MySQL on the Web
» Problem Solution Discussion Basic Web Page Generation
» Problem Solution Discussion Using Apache to Run Web Scripts
» Problem Solution Discussion Using Tomcat to Run Web Scripts
» Installing the mcb Application
» Installing the JSTL Distribution
» Problem Solution Discussion Encoding Special Characters in Web Output
» General Encoding Principles Encoding Special Characters in Web Output
» Encoding Special Characters Using Web APIs
» Introduction Incorporating Query Results into Web Pages
» Problem Solution Discussion Creating a Navigation Index from Database Content
» Creating a Multiple-Page Navigation Index
» Problem Solution Discussion Storing Images or Other Binary Data
» Storing Images with LOAD_FILE Storing Images Using a Script
» Problem Solution Discussion Retrieving Images or Other Binary Data
» Problem Solution Discussion Serving Banner Ads
» Problem Solution Discussion Serving Query Results for Download
» Introduction Processing Web Input with MySQL
» Problem Solution Discussion Creating Forms in Scripts
» Problem Solution Discussion Creating Multiple-Pick Form Elements from Database Content
» Problem Solution Discussion Loading a Database Record into a Form
» Problem Solution Discussion Collecting Web Input
» Web Input Extraction Conventions Perl
» Problem Solution Discussion Validating Web Input
» Problem Solution Discussion Using Web Input to Construct Queries
» Problem Solution Discussion Processing File Uploads
» Perl Processing File Uploads
» Problem Solution Discussion Performing Searches and Presenting the Results
» Problem Solution Discussion Generating Previous-Page and Next-Page Links
» Paged Displays with Previous-Page and Next-Page Links
» Paged Displays with Links to Each Page
» Problem Solution Discussion Web Page Access Counting
» Problem Solution Discussion Web Page Access Logging
» Problem Solution Discussion Setting Up Database Logging
» Other Logging Issues Using MySQL for Apache Logging
» Session Management Issues Introduction
» Problem Solution Discussion Installing Apache::Session
» The Apache::Session Interface
» A Sample Application Using MySQL-Based Sessions in Perl Applications
» Problem Solution Discussion The PHP 4 Session Management Interface
» Specifying a User-Defined Storage Module
» Problem Solution Discussion Using MySQL for Session BackingStore with Tomcat
» The Servlet and JSP Session Interface A Sample JSP Session Application
Show more