It's 2019 and PHP is *still* teaching people to concatenate SQL and vaguely-sanitized user input instead of using prepared statements. http://php.net/manual/en/mysqli.examples-basic.php … They got rid of the mysql module... only to teach people to use mysqli the same way. This is why SQLi isn't going away.
-
-
Replying to @marcan42
It's not an excuse but just in case you didn't know, I believe that particular php doc site is wiki-like, ie you/we could fix this
1 reply 0 retweets 0 likes -
Or at least perhaps put a big red warning on it saying 'dont actaully do this' I suppose
1 reply 0 retweets 0 likes
Replying to @mopman
Sure, but the fact that the PHP community hasn't fixed literally the first result every newbie is going to find to talk to a database with PHP is just a massive reflection of how terrible they still are at security. Decades of SQL injections and this is what they're teaching?
11:12 AM - 26 Jan 2019
0 replies
0 retweets
5 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.