PHP coders: SQL injection

Discussion in 'Programming' started by BusinessCoach, Mar 31, 2008.

  1. #1
    i need someone who is familiar with this to take a look at some code for a site of mine, and determine if it is vulnerable to this sort of attack

    and if so, what it would take to correct this issue

    and an estimated price for you to do so

    contact me via IM
     
    BusinessCoach, Mar 31, 2008 IP
  2. BusinessCoach

    BusinessCoach Well-Known Member

    Messages:
    1,719
    Likes Received:
    51
    Best Answers:
    0
    Trophy Points:
    185
    As Seller:
    100% - 2
    As Buyer:
    100% - 0
    #2
    still looking

    please note:

    --there are 120+ files in the main directory

    plus 50 folders with dozens or hundreds of files

    so we need an automated way or at least simple way to check the site.

    we won't be zipping up the entire site and sending it to you.


    --also DO NOT ASK FOR UP FRONT PAYMENT if you have a ZERO trader rating and no references of work like this done before.


    --IM, not PM please..thanks
     
    BusinessCoach, Mar 31, 2008 IP
  3. SimThePhpCoder

    SimThePhpCoder Well-Known Member

    Messages:
    949
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    108
    As Seller:
    100% - 0
    As Buyer:
    100% - 0
    #3
    all you gotta do is put mysql_real_escape_string() around all your $_GET[]'s and $_POST[]'s
     
    SimThePhpCoder, Mar 31, 2008 IP