3 ms·
TL;DR: This doesn't really do what it claims to do (prevent injection), but it does slightly mitigate some attack vectors. It's security through obscurity, whic
by tetrep 8y ago
TL;DR: This doesn't really do what it claims to do (prevent injection), but it does slightly mitigate some attack vectors. It's security through obscurity, which is useful as defense in depth (see: ASLR), but hardly stops all attacks (or even a motivated attacker). If someone ran around declaring the end of buffer overflow exploits because of ASLR, I'd have a hearty chuckle.
root:/pwd# cat scrambled.php
<?php
arFktyO “Hello, “;
arFktyO “Small World.\n”;
?>
In the above example, arFktyO = echo. This doesn't fix (imo) the most common instance of [something]-injection, which usually stems from string concatenation, i.e.
sqlQuery = "SELECT * FROM table WHERE owner=" + userInput
execute(sqlQuery)
or
command = "ls " + userInput
eval(command)
- joe_the_user 8y agoThe problem is this isn't just security-through-obscurity and but also roll-your-own-encryption, because it's filter is effectively just testing whether commands have been shuffled with a homemade shuffler. And I think roll-your-own-encryption is much more in the realm of always-bad. Edit: as others say, why use this instead of code-signing.
- ben509 8y agoYou don't need a particularly advanced DBMS to create a schema with views that have scrambled names, or just stored procedures with scrambled names. CREATE VIEW oijweojf AS SELECT thing AS woeifj, stuff AS pokkx Similarly, if you're shelling out, you can certainly set up a chroot jail with all the names scrambled. That said, you then need to integrate all this into a build and deploy process, and god help anyone who has to debug it.
- hyperhopper 8y agoscrambling those names is equivalent to scrambling variable names. The actual use of this tool would be the equivalent of scrambling `CREATE VIEW` to `kdjal fjdskalf`