Re: Correct escaping of untrusted data - Mailing list pgsql-general

From Olivier Guilyardi
Subject Re: Correct escaping of untrusted data
Date
Msg-id 410BF692.9000604@xung.org
Whole thread Raw
In response to Correct escaping of untrusted data  (Geoff Caplan <geoff@variosoft.com>)
List pgsql-general
Geoff Caplan wrote:

> Are the standard escaping functions found in the PHP, Tcl etc APIs to
> Postgres bombproof? Are there any encodings that might slip through
> and be cast to malicious strings inside Postgres? What about functions
> like convert(): could they be used to slip something through the
> escaping function?

What about writing nessus plugin(s) or a specific scanner for these
escaping issues ? I don't know if a such thing already exists...

--
     Olivier

pgsql-general by date:

Previous
From: Tom Lane
Date:
Subject: Re: How to use as Functional Index to be used as Primary KEY
Next
From: Joel Rodrigues
Date:
Subject: Fwd: [NOVICE] contrib/xml make error on Mac OS X 10.3.4