如何消除Checkmarx对PHP预处理语句的Second-Order SQL Injection误报?
如何消除Checkmarx对预编译SQL函数的二阶注入误报?
自定义PHP预编译插入函数
我编写了一个用于创建预编译语句的自定义PHP函数,代码如下:
function insertUsingPreparedStmt($table, $params, $bind_condition) { $dbobj = $this->getMysqliObject(); $fields = array_keys($params); $values = array_values($params); $question_mark = ''; foreach ($values as $id) $question_mark .= '?, '; $question_mark = rtrim($question_mark, ', '); $bind_params[] = &$bind_condition['bind_type']; $n = count($values); for ($i = 0; $i < $n; $i++) { $bind_params[] = &$values[$i]; } $query = "INSERT INTO $table (" . implode(" , ", $fields) . ") VALUES ( $question_mark )"; $stmt = $dbobj->prepare($query); call_user_func_array(array($stmt, 'bind_param'), $bind_params); $stmt->execute(); $stmt->close(); }
Checkmarx误报提示
由于该函数使用了预编译语句,不存在二阶SQL注入风险,但Checkmarx检测提示:
Method
executeStoreProcedureat line 994 ofapp/Mysqlim.phpgets database data from thefetch_objectelement. This element’s value then flows through the code without being properly sanitized or validated, and is eventually used in a database query in methodinsertUsingPreparedStmtat line 1568 ofapp/Mysqlim.php. This may enable an Second-Order SQL Injection attack.
目前共有12条此类检测结果,均为误报,以下是在Checkmarx中消除这些误报的方法:
- 标记误报:在Checkmarx扫描结果中找到对应的告警条目,选择标记为「误报(False Positive)」,添加备注说明原因(例如:“该函数采用mysqli预编译语句,所有参数通过
bind_param绑定,无直接拼接SQL的风险,不存在二阶注入可能”),提交后这些告警会被系统过滤,不再显示。 - 添加忽略注释:在
insertUsingPreparedStmt函数开头或相关风险代码行添加Checkmarx支持的忽略注释,例如:// CHECKMARX: SKIP Second-Order SQL Injection,不同版本的Checkmarx注释语法可能略有差异,建议参考官方文档确认。 - 调整扫描规则:如果是团队环境,联系Checkmarx管理员,针对二阶SQL注入的检测规则添加例外,将
insertUsingPreparedStmt函数排除在该规则的检测范围之外,从根源上避免此类误报。 - 优化代码辅助识别:可以给表名和字段名添加显式的白名单校验(比如验证
$table是否属于系统允许的表名列表,$fields是否对应目标表的合法字段),让Checkmarx识别到输入经过了严格校验,减少误判。
内容的提问来源于stack exchange,提问作者fahad shaikh
相关产品推荐
相关产品推荐

