Security Concerns with having sql queries in swf files

EmperorIQ

Platinum Member
Sep 30, 2003
2,003
0
0
I have swf where I communicate to the database via php. A sql query is passed to the php file, and the php file makes a call to the database with the query.

What are the security concerns with having sql queries in your swf file? I've been searching for a while and all I have found are ways on communicating to the database with flex. I have yet to find anything with respect to having sql queries coded in your swf. I'm just a bit worried as swf files can be decompiled and people can see the code.

Thanks!
 

troytime

Golden Member
Jan 3, 2006
1,996
1
0
i haven't touched flash in 10 years, but my guess would be the same as yours - swf files can be downloaded. if someone can see the query, it can give them information that they're not supposed to have

keep the query in a php file
 

GeekDrew

Diamond Member
Jun 7, 2000
9,100
13
81
I know nothing about swf, but if they can be decompiled, and your PHP script is just passing the query to the db server, wouldn't that then allow an attacker to execute any arbitrary query against the database?
 

EmperorIQ

Platinum Member
Sep 30, 2003
2,003
0
0
Hmm... so its probably best to keep the query in the php files, and have the swf just know what php file to call for whatever data it needs.
 

DaveSimmons

Elite Member
Aug 12, 2001
40,730
670
126
The SWF is just as insecure as if you were making the call from javascript code running in the browser.

Also assume that anyone who cares can use a packet sniffer to see what PHP page is being called and what parameters are being passed to it. After that, they can easily make a request directly to the PHP page without using your SWF.

You might want to pass something like "1" or "2" (for query type #1, type #2) + any flags/parameters instead of raw SQL, and have the PHP page build the query from that.

lookup.php ? qtype=1 & id=(user ID) >> returns list of orders

lookup.php ? qtype=3 & id=(user ID) & oud=(order-id) >> returns tracking for order (order-id)

This can be even stonger than sanitizing SQL queries since the queries are hard-coded in the PHP code. You still need to validate each of the CGI variables though since an attacker can try passing unexpected qtypes and IDs.
 

NiKeFiDO

Diamond Member
May 21, 2004
3,901
1
76
Originally posted by: EmperorIQ
Hmm... so its probably best to keep the query in the php files, and have the swf just know what php file to call for whatever data it needs.

Exactly - Only have the Flash pass get or post parameters to your php files which will do the rest of the processing.

You should keep the database name / user / password in a file outside of the WWW / public_html / httpdocs / whatever it is on your server folder (in your php files that is inside of the www folder, you should just be able to do include('../paswords.php');
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |