doubo4824 2014-11-26 14:26
浏览 9
已采纳

CakePHP清理参数

I have the following method in my CakePHP model:

public function login($login,$password){

    $arr = $this->find('first',array(
        'conditions' => array(
            'deleted' => 0,
            'online' => 1,
            'login' => $login,
            'AES_DECRYPT(UNHEX(password),'secretkey')=\''.$password.'\''
        )
    ));


    return $arr;
}

This method accepts two parameters ($login, $password) to authenticate the user.

I am wondering if this method is safe against SQL-Injection and other attacks.

If not, which is the best way to sanitize the input parameters using CakePHP?

I see that the Sanitize Class is deprecated as of 2.4.

  • 写回答

3条回答 默认 最新

  • douyan1896 2014-11-26 18:33
    关注

    Model::find() is only safe when used properly!

    You must know that only values in key => value pairs are being escaped, keys and non/numerically keyd values are inserted into the SQL query as is!

    Quote from the docs

    CakePHP only escapes the array values. You should never put user data into the keys. Doing so will make you vulnerable to SQL injections.

    http://book.cakephp.org/2.0/en/models/retrieving-your-data.html#complex-find-conditions

    So your find() call as is, is unsafe and prone to SQL injections, it should instead look like this:

    $arr = $this->find('first',array(
        'conditions' => array(
            'deleted' => 0,
            'online' => 1,
            'login' => $login,
            'AES_DECRYPT(UNHEX(password),\'secretkey\')' => $password
        )
    ));
    

    That way the user input $login and $password is being escaped properly.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(2条)

报告相同问题?

悬赏问题

  • ¥15 HFSS 中的 H 场图与 MATLAB 中绘制的 B1 场 部分对应不上
  • ¥15 如何在scanpy上做差异基因和通路富集?
  • ¥20 关于#硬件工程#的问题,请各位专家解答!
  • ¥15 关于#matlab#的问题:期望的系统闭环传递函数为G(s)=wn^2/s^2+2¢wn+wn^2阻尼系数¢=0.707,使系统具有较小的超调量
  • ¥15 FLUENT如何实现在堆积颗粒的上表面加载高斯热源
  • ¥30 截图中的mathematics程序转换成matlab
  • ¥15 动力学代码报错,维度不匹配
  • ¥15 Power query添加列问题
  • ¥50 Kubernetes&Fission&Eleasticsearch
  • ¥15 報錯:Person is not mapped,如何解決?