downloads | documentation | faq | getting help | mailing lists | licenses | wiki | reporting bugs | php.net sites | links | conferences | my php.net

search for in the

Running the Driver's Tests> <php.ini Options
Last updated: Fri, 20 May 2011

view this page in

Security

Request Injection Attacks

If you are passing $_GET parameters to your queries, make sure that they are cast to strings first. Users can insert associative arrays in GET requests, which could then become unwanted $-queries.

A fairly innocuous example: suppose you are looking up a user's information with the request http://www.example.com?username=bob. Your application does the query $collection->find(array("username" => $_GET['username'])).

Someone could subvert this by getting http://www.example.com?username[$ne]=foo, which PHP will magically turn into an associative array, turning your query into $collection->find(array("username" => array('$ne' => "foo"))), which will return all users not named "foo" (all of your users, probably).

This is a fairly easy attack to defend against: make sure $_GET's parameters are the type you expect before you send them to the database (cast them to strings, in this case).

Thanks to » Phil for pointing this out.

See » the main documentation for more information about SQL-injection-like issues with MongoDB.



add a note add a note User Contributed Notes Security
Mark Caudill 08-Mar-2011 06:18
This also occurs using POST (obviously) despite it not being mentioned.  Sanitize all input you are taking in that can cause this issue.

 
show source | credits | stats | sitemap | contact | advertising | mirror sites