Monday, December 22, 2008

Prevent your Php MySQL scripts from SQL injections

If your site uses data from user and operates its database functionalities over it then you are not safe. SQL injections are the most comman type of attack which a site faces. I would like to mention some common types of attacks and how to save your script from these attacks.

Escape your input strings
Consider a query
"select * from users where username = '{$userid}' "
input : $userid = " 1'; delete from users"
so the query would become 
"select * from users where username = '1'; delete from users"
A query is injected to delete all the data in users table. But luckily mySql doesn't support query stacking hence more than one queries can't be executed. But this attack can occur in other databases like pgsql and ms sql which supports query stacking.
But still the input is not save . consider another input
$userid = " 1' OR '1' = '1' "
query becomes :
"select * from users where username = '1' OR '1' = '1' "
since 1 = 1 always the attack is successfull. So you must escape quotations from user input. Standard way of escaping will be:

function escape($data)
{
if ( get_magic_quotes_gpc() )
$data = stripslashes($data);
return mysql_real_escape_string($data);
}

Magic quotes should be checked for .. as if they are 'on' then your data will be escaped twice .. You might ask if you can use addslashes in place of mysql_real_escape_string as both escapes special characters .. but cases have been found in which addslashes failed against sql injections .. I won't go into much details of it .

mysql_real_escape_string escapes characters:  \x00, \n, \r, \, ', " and \x1a .

When quotations are not used
What if your query doesn't contain a quotation. Example
select * from users where id = $userid
and $userid = 1 OR 1 = 1
which will become
"select * from users where id = 1 OR 1 = 1"
But we have escaped quote .. and since simple int doesn't require to be quoted your query again became vulnerable.. what we can do in this case is to cast an input ..
$userid = (int)1 OR 1 = 1 //$userid = 1
or in case the input is a float we can cast it as a float to ensure that the data coming is of required type.

% and _ are not escaped still
Consider this query:
select * from users where date LIKE '{$date}%'
$date = "%" // we expected something like 2008-12
an attacker can use % and _ too ... they must also be escaped.. php provides a custom escaping function addcslashes.. we can further escape our data like this
$data = escape($data); // above escape function
addcslashes($data,"%_");
And all % and _ will also be escaped which culd attack on LIKE based queries.

Prevent your schema details from user
if you do query something like 
mysql_query ($query) or die(mysql_error());
the function mysql_error() can reveal certain details about your tables and field names. Try some other approach. Maybe you could store errors in a private log file which only you can read.

These were only some of the tips. Users of your web site are your evil enemies. Gmail, wikipedia and other big names all were attacked like this. Also keep your script save from these attacks by using above tips and more if you can. Good luck !

Monday, September 8, 2008

Victory at Combat 08,PAF KIET in a Programming Competition !!!!!!!

This is the first blog post by me … I was never a blogger but this event is worth writing and remembering  so I thought why not a blog post for it .

So let me start from the beginning. Me, Amir Ali  and Abeer are a group and we use to participate in different programming competitions. So as usual we also participated in this event together.

It was 23rd of August 2008. In the morning we started out at 10:00 but had very little idea where this university is located … We took a rickshaw and tried to find this university … Our journey was thrilling … we went in wrong directions and then asked many people to help show us the right path … we were stucked there that for a moment I think that we wont be able to reach or it will be of no use for us to participate then after getting so late … but we never lose hope … after 2 hrs of struggle we reached there …

A guy out there shocked us when he said that its started 1.5 hrs back … we moved more fast and when we reached inside the university it was so nice to see all the people from our university sitting on benches and waiting for the competition to start …

Just then the competition start and we started on the most fruitful programming competition of our life … we 3 were the strongest team …  after 1 hrs and 50 minutes we were able to complete 3 questions out of 5 … then we were presented the score board which declared us on the top position at that moment …  Oh my God …what a feeling …we were the most happiest persons on the earth … but then we couldn’t do more questions as we didn’t know some algorithms … and one of the team made it to the top leaving us at 2nd position .

After the competition ended … at night there was a ceremony arranged by Paf kietiens to award the winning teams … after a round of dry speeches …  it was time to announce winners of Programming competition … The group at the 1st position got 60,000 Rs cash along with some scholarship … We were at the second position … we received cash prize of Rs. 30,000 ( 10 k for each :P ) … and some scholarship too … with lots of congrats from people around and our dear Ali Bhai ( C.E.O.  nuvica Pakistan ) who was with us all that day … We then had a khapa … and left at around 11 …

The biggest happiness we got is that now in our university many people have known us … and we have high esteem in faculty and students :).

Amir Ali himself have blogged about this ... and you can view a detailed version of this story there :P

Saturday, September 6, 2008

Helloo World

Hello world ... This is my very own blog and its this is my first post ... !!!