Search
Archives
- August 2015 (1)
- September 2014 (1)
- June 2014 (2)
- January 2014 (1)
- September 2012 (1)
- July 2012 (1)
- April 2012 (1)
- January 2012 (2)
- June 2011 (2)
- November 2010 (1)
- October 2010 (1)
- May 2010 (2)
- April 2010 (1)
- December 2009 (1)
- November 2009 (1)
- August 2009 (1)
- June 2009 (1)
- April 2009 (1)
- January 2009 (5)
- December 2008 (1)
- November 2008 (1)
- August 2008 (3)
- July 2008 (3)
- June 2008 (1)
- February 2008 (2)
- January 2008 (1)
- November 2007 (2)
- September 2007 (1)
- July 2007 (1)
- May 2007 (2)
Categories
Meta
Category Archive: Web
Subcategories: No categories
PHP and SQL injection
Ok, being someone who likes php, i get annoyed at the many sites trying to teach people the language who have example login scripts that use something like:
$result=mysql_query("select * from users where Username=$username and Password=$password"); if (mysql_num_rows($result) < 1) blah blah blah
Whats wrong with that you ask? Well imagine what would happen if someone were to use the username '' or 1=1 #
(more…)