WEBVTT 1 00:00:01.550 --> 00:00:04.490 in the previous video saw how to use the 2 00:00:04.490 --> 00:00:07.069 connection and cursor objects to execute in the previous video saw how to use the 3 00:00:07.069 --> 00:00:10.130 sql queries against out database and connection and cursor objects to execute 4 00:00:10.130 --> 00:00:12.140 also hopefully they've got an idea on sql queries against out database and 5 00:00:12.140 --> 00:00:14.059 how important it is to commit your also hopefully they've got an idea on 6 00:00:14.059 --> 00:00:15.920 changes to the database when you're how important it is to commit your 7 00:00:15.920 --> 00:00:18.529 inserting or updating data but in this changes to the database when you're 8 00:00:18.529 --> 00:00:19.669 video we're going to look at inserting or updating data but in this 9 00:00:19.669 --> 00:00:22.699 placeholders and parameter substitution video we're going to look at 10 00:00:22.699 --> 00:00:24.800 alright so what are they and what's the placeholders and parameter substitution 11 00:00:24.800 --> 00:00:26.359 problem more importantly that they're alright so what are they and what's the 12 00:00:26.359 --> 00:00:28.579 actually designed to solve let's problem more importantly that they're 13 00:00:28.579 --> 00:00:30.019 actually have a look at our original actually designed to solve let's 14 00:00:30.019 --> 00:00:33.530 update query in the contacts 2 actually have a look at our original 15 00:00:33.530 --> 00:00:35.780 . query going to change the code back update query in the contacts 2 16 00:00:35.780 --> 00:00:37.789 to what it was before we actually have . query going to change the code back 17 00:00:37.789 --> 00:00:40.460 changed it we had this where clause so to what it was before we actually have 18 00:00:40.460 --> 00:00:47.210 ...and if you changed it we had this where clause so 19 00:00:47.210 --> 00:00:50.210 recall the actual update was update ...and if you 20 00:00:50.210 --> 00:00:52.489 .com but i'm actually recall the actual update was update 21 00:00:52.489 --> 00:00:57.170 going to changes .com but i'm actually 22 00:00:57.170 --> 00:00:58.760 and I've done that so that we can going to changes 23 00:00:58.760 --> 00:00:59.929 actually see that things are being and I've done that so that we can 24 00:00:59.929 --> 00:01:01.640 changed when we eventually re run this actually see that things are being 25 00:01:01.640 --> 00:01:04.250 query now the problem with this is that changed when we eventually re run this 26 00:01:04.250 --> 00:01:05.960 where we left it in the previous video query now the problem with this is that 27 00:01:05.960 --> 00:01:08.899 is that we hard coded the new email where we left it in the previous video 28 00:01:08.899 --> 00:01:11.390 address and also the condition in the is that we hard coded the new email 29 00:01:11.390 --> 00:01:13.159 sql statement the where clause address and also the condition in the 30 00:01:13.159 --> 00:01:15.710 normally you'd want to provide these sql statement the where clause 31 00:01:15.710 --> 00:01:18.440 details from variables a program that normally you'd want to provide these 32 00:01:18.440 --> 00:01:20.570 can only set the email address to another details from variables a program that 33 00:01:20.570 --> 00:01:23.299 update update. com for rows where can only set the email address to another 34 00:01:23.299 --> 00:01:25.939 the phone number was 1234 would be a bit update update. com for rows where 35 00:01:25.939 --> 00:01:28.070 limited to say the least the phone number was 1234 would be a bit 36 00:01:28.070 --> 00:01:30.740 so let's create a couple of variables to limited to say the least 37 00:01:30.740 --> 00:01:33.050 store the new email address and the so let's create a couple of variables to 38 00:01:33.050 --> 00:01:35.539 phone number so i'm going to add those to line 5 store the new email address and the 39 00:01:35.539 --> 00:01:38.420 we're going to start with new phone number so i'm going to add those to line 5 40 00:01:38.420 --> 00:01:41.210 email so... we're going to start with new 41 00:01:41.210 --> 00:01:43.700 .... email so... 42 00:01:43.700 --> 00:01:49.940 .... .... 43 00:01:49.940 --> 00:01:54.770 ....now we could .... 44 00:01:54.770 --> 00:01:56.720 use the string formatting that were ....now we could 45 00:01:56.720 --> 00:01:58.819 already familiar and changed use the string formatting that were 46 00:01:58.819 --> 00:02:07.830 line 8 to something like this already familiar and changed 47 00:02:07.830 --> 00:02:16.770 so we could do that and that would line 8 to something like this 48 00:02:16.770 --> 00:02:18.600 actually work fine in fact lets actually so we could do that and that would 49 00:02:18.600 --> 00:02:20.760 run that just to confirm that does work actually work fine in fact lets actually 50 00:02:20.760 --> 00:02:26.340 and you can see that only the record run that just to confirm that does work 51 00:02:26.340 --> 00:02:30.120 brian with the ID 1234 got his and you can see that only the record 52 00:02:30.120 --> 00:02:30.990 email address brian with the ID 1234 got his 53 00:02:30.990 --> 00:02:33.600 updated to another update update .com so email address 54 00:02:33.600 --> 00:02:36.000 clearly that update actually worked and updated to another update update .com so 55 00:02:36.000 --> 00:02:37.980 the string formatting that put in place clearly that update actually worked and 56 00:02:37.980 --> 00:02:41.040 has actually done the job but what would the string formatting that put in place 57 00:02:41.040 --> 00:02:43.200 happen if we allowed the phone number to has actually done the job but what would 58 00:02:43.200 --> 00:02:44.910 be type-in by user so let's actually happen if we allowed the phone number to 59 00:02:44.910 --> 00:02:46.860 change the program slightly to see that be type-in by user so let's actually 60 00:02:46.860 --> 00:02:48.810 i'm going to leave the new email change the program slightly to see that 61 00:02:48.810 --> 00:02:51.300 addresses as it was and put... i'm going to leave the new email 62 00:02:51.300 --> 00:02:58.950 .... addresses as it was and put... 63 00:02:58.950 --> 00:03:04.950 ...so I actually run that now please .... 64 00:03:04.950 --> 00:03:06.360 enter the phone number so if I actually enter the ...so I actually run that now please 65 00:03:06.360 --> 00:03:12.630 phone number 1234 you can see we've got enter the phone number so if I actually enter the 66 00:03:12.630 --> 00:03:15.269 one row updated here so clearly the phone number 1234 you can see we've got 67 00:03:15.269 --> 00:03:17.459 updates work we don't see any different one row updated here so clearly the 68 00:03:17.459 --> 00:03:18.870 because the new email address is already updates work we don't see any different 69 00:03:18.870 --> 00:03:20.489 been updated but you can see that our because the new email address is already 70 00:03:20.489 --> 00:03:22.290 codes working now been updated but you can see that our 71 00:03:22.290 --> 00:03:24.269 at the moment we're only executing a codes working now 72 00:03:24.269 --> 00:03:26.519 single update query and python is at the moment we're only executing a 73 00:03:26.519 --> 00:03:28.590 actually quite clever and won't allow single update query and python is 74 00:03:28.590 --> 00:03:30.720 multiple statements to be used when we actually quite clever and won't allow 75 00:03:30.720 --> 00:03:33.930 call the execute method but sometimes multiple statements to be used when we 76 00:03:33.930 --> 00:03:34.980 you want to do that so I'm going to call the execute method but sometimes 77 00:03:34.980 --> 00:03:38.340 actually alter line 11 here actually what I'll you want to do that so I'm going to 78 00:03:38.340 --> 00:03:40.470 do first is after the update actually alter line 11 here actually what I'll 79 00:03:40.470 --> 00:03:42.780 lets actually print that out.... do first is after the update 80 00:03:42.780 --> 00:03:45.360 .... lets actually print that out.... 81 00:03:45.360 --> 00:03:51.390 .....here on line 11 we're actually gonna .... 82 00:03:51.390 --> 00:03:52.950 leave that line as it is but thus next line .....here on line 11 we're actually gonna 83 00:03:52.950 --> 00:03:55.350 is where it's got update cursor . leave that line as it is but thus next line 84 00:03:55.350 --> 00:03:58.709 execute going to change that to execute is where it's got update cursor . 85 00:03:58.709 --> 00:04:04.260 script.....lets also change the execute going to change that to execute 86 00:04:04.260 --> 00:04:05.880 email address so we can really confirm script.....lets also change the 87 00:04:05.880 --> 00:04:08.370 this is working... email address so we can really confirm 88 00:04:08.370 --> 00:04:09.720 .... this is working... 89 00:04:09.720 --> 00:04:13.530 so let's actually run that again please .... 90 00:04:13.530 --> 00:04:15.880 enter the phone number so let's actually run that again please 91 00:04:15.880 --> 00:04:19.660 and we can see the update has enter the phone number 92 00:04:19.660 --> 00:04:21.970 proceeded and by the way you get minus and we can see the update has 93 00:04:21.970 --> 00:04:25.570 one rows updated here the execute proceeded and by the way you get minus 94 00:04:25.570 --> 00:04:27.220 script method doesn't actually set the one rows updated here the execute 95 00:04:27.220 --> 00:04:29.440 row count properly so therefore you can script method doesn't actually set the 96 00:04:29.440 --> 00:04:31.510 ignore that particular value showing row count properly so therefore you can 97 00:04:31.510 --> 00:04:33.220 their but overall we can see that ignore that particular value showing 98 00:04:33.220 --> 00:04:35.350 everything is working fine in that their but overall we can see that 99 00:04:35.350 --> 00:04:37.720 the email address was updated now why everything is working fine in that 100 00:04:37.720 --> 00:04:39.460 do i use the execute script method for the email address was updated now why 101 00:04:39.460 --> 00:04:41.800 well that method is designed for running do i use the execute script method for 102 00:04:41.800 --> 00:04:43.540 more than one sql statement in a well that method is designed for running 103 00:04:43.540 --> 00:04:46.030 single call now the individual more than one sql statement in a 104 00:04:46.030 --> 00:04:47.470 statements must be separated by single call now the individual 105 00:04:47.470 --> 00:04:50.290 semicolons and python will execute them statements must be separated by 106 00:04:50.290 --> 00:04:52.510 one after the other and I know right now semicolons and python will execute them 107 00:04:52.510 --> 00:04:54.160 we've only got a single statement here one after the other and I know right now 108 00:04:54.160 --> 00:04:56.050 but if I'd use multiple statements it we've only got a single statement here 109 00:04:56.050 --> 00:04:58.270 would just be confusing make it harder but if I'd use multiple statements it 110 00:04:58.270 --> 00:05:00.220 to see what's going on in this next bit would just be confusing make it harder 111 00:05:00.220 --> 00:05:01.810 alright so i want to show you know to see what's going on in this next bit 112 00:05:01.810 --> 00:05:06.040 something by running it again this time alright so i want to show you know 113 00:05:06.040 --> 00:05:07.870 we're going to type in the numbers 1 2 3 something by running it again this time 114 00:05:07.870 --> 00:05:13.060 4 semicolon drop tables or dropped table... we're going to type in the numbers 1 2 3 115 00:05:13.060 --> 00:05:18.880 ....and we 4 semicolon drop tables or dropped table... 116 00:05:18.880 --> 00:05:20.470 actually get an error at this point ....and we 117 00:05:20.470 --> 00:05:22.840 specifically the error we are looking at actually get an error at this point 118 00:05:22.840 --> 00:05:24.220 is down here on the bottom specifically the error we are looking at 119 00:05:24.220 --> 00:05:27.550 no such table contacts so it's obviously is down here on the bottom 120 00:05:27.550 --> 00:05:28.960 something pretty serious has happened no such table contacts so it's obviously 121 00:05:28.960 --> 00:05:32.020 here and you can actually print have a something pretty serious has happened 122 00:05:32.020 --> 00:05:34.420 look at the SQL statement that we here and you can actually print have a 123 00:05:34.420 --> 00:05:36.250 printed out the code we added to line 9 look at the SQL statement that we 124 00:05:36.250 --> 00:05:38.140 you can see what happened here printed out the code we added to line 9 125 00:05:38.140 --> 00:05:41.830 the two sql statements here so you can see what happened here 126 00:05:41.830 --> 00:05:43.750 you see our valid update but then the two sql statements here so 127 00:05:43.750 --> 00:05:45.820 followed by a drop table contacts and you see our valid update but then 128 00:05:45.820 --> 00:05:46.990 obviously we know what that does that followed by a drop table contacts and 129 00:05:46.990 --> 00:05:49.000 actually physically drops the table from obviously we know what that does that 130 00:05:49.000 --> 00:05:50.140 the database actually physically drops the table from 131 00:05:50.140 --> 00:05:52.720 oops and that's an understatement i'm the database 132 00:05:52.720 --> 00:05:55.090 going to switch back to our check DB oops and that's an understatement i'm 133 00:05:55.090 --> 00:06:00.430 and just run that just to confirm and we going to switch back to our check DB 134 00:06:00.430 --> 00:06:02.110 haven't got a table so the table and just run that just to confirm and we 135 00:06:02.110 --> 00:06:03.250 has been dropped haven't got a table so the table 136 00:06:03.250 --> 00:06:05.590 what just happened here is known as a has been dropped 137 00:06:05.590 --> 00:06:08.440 sql injection attack this is where an what just happened here is known as a 138 00:06:08.440 --> 00:06:11.170 attacker injects sql statements into sql injection attack this is where an 139 00:06:11.170 --> 00:06:14.920 the sql that a program executes now a attacker injects sql statements into 140 00:06:14.920 --> 00:06:16.660 relatively short time ago the sql that a program executes now a 141 00:06:16.660 --> 00:06:18.310 it really was a simple as I've just relatively short time ago 142 00:06:18.310 --> 00:06:20.650 demonstrated an attacker with a good it really was a simple as I've just 143 00:06:20.650 --> 00:06:22.720 knowledge of sql was able to craft demonstrated an attacker with a good 144 00:06:22.720 --> 00:06:24.850 their input so that additional knowledge of sql was able to craft 145 00:06:24.850 --> 00:06:27.409 sql statements would be executed their input so that additional 146 00:06:27.409 --> 00:06:29.059 you might be thinking at this point but sql statements would be executed 147 00:06:29.059 --> 00:06:30.830 hang on to tim you have to know the name you might be thinking at this point but 148 00:06:30.830 --> 00:06:33.559 of the table let's just see how hard it hang on to tim you have to know the name 149 00:06:33.559 --> 00:06:35.719 is to find out as long as we know the of the table let's just see how hard it 150 00:06:35.719 --> 00:06:38.209 type of database you're attacking and is to find out as long as we know the 151 00:06:38.209 --> 00:06:39.589 even if the site doesn't have something type of database you're attacking and 152 00:06:39.589 --> 00:06:41.539 like powered by Microsoft sql server even if the site doesn't have something 153 00:06:41.539 --> 00:06:43.819 displayed at the bottom of the page a few like powered by Microsoft sql server 154 00:06:43.819 --> 00:06:46.039 carefully crafted queries will soon displayed at the bottom of the page a few 155 00:06:46.039 --> 00:06:48.979 determine which database is being used carefully crafted queries will soon 156 00:06:48.979 --> 00:06:50.899 well so we'll assume at this point we've determine which database is being used 157 00:06:50.899 --> 00:06:53.659 worked out that were attacking a sql well so we'll assume at this point we've 158 00:06:53.659 --> 00:06:56.239 lite database going to start by running our worked out that were attacking a sql 159 00:06:56.239 --> 00:06:58.159 original contacts .py program again lite database going to start by running our 160 00:06:58.159 --> 00:06:59.929 because that's going to recreate the original contacts .py program again 161 00:06:59.929 --> 00:07:00.709 table because that's going to recreate the 162 00:07:00.709 --> 00:07:05.629 let's do that....will just go table 163 00:07:05.629 --> 00:07:07.429 back into checked db just to confirm let's do that....will just go 164 00:07:07.429 --> 00:07:10.069 that the tables back again you can see back into checked db just to confirm 165 00:07:10.069 --> 00:07:12.559 and that's working and now that i've that the tables back again you can see 166 00:07:12.559 --> 00:07:13.729 confirmed that's working lets actually and that's working and now that i've 167 00:07:13.729 --> 00:07:15.439 make a change here instead of select confirmed that's working lets actually 168 00:07:15.439 --> 00:07:18.559 star from contacts going to do select star make a change here instead of select 169 00:07:18.559 --> 00:07:21.259 ....you can see it's star from contacts going to do select star 170 00:07:21.259 --> 00:07:22.879 actually come up quite helpful IntelliJ ....you can see it's 171 00:07:22.879 --> 00:07:25.249 told at the table looking to work on actually come up quite helpful IntelliJ 172 00:07:25.249 --> 00:07:29.329 so when I actually run that we get told at the table looking to work on 173 00:07:29.329 --> 00:07:31.849 the full details of all the tables in so when I actually run that we get 174 00:07:31.849 --> 00:07:34.610 the database so injecting that select the full details of all the tables in 175 00:07:34.610 --> 00:07:36.469 query when you know the results will be the database so injecting that select 176 00:07:36.469 --> 00:07:39.349 displayed such as in a retail stock query when you know the results will be 177 00:07:39.349 --> 00:07:41.360 search page for example can provide a displayed such as in a retail stock 178 00:07:41.360 --> 00:07:43.550 lot of information about the database search page for example can provide a 179 00:07:43.550 --> 00:07:46.879 structure now sql injection attacks lot of information about the database 180 00:07:46.879 --> 00:07:48.889 were actually very common and successful structure now sql injection attacks 181 00:07:48.889 --> 00:07:51.019 for a while they're actually still a were actually very common and successful 182 00:07:51.019 --> 00:07:53.389 serious problem but because database for a while they're actually still a 183 00:07:53.389 --> 00:07:55.219 administrators and programmers that's us serious problem but because database 184 00:07:55.219 --> 00:07:57.439 by the way and now aware of them administrators and programmers that's us 185 00:07:57.439 --> 00:07:59.239 it's much harder to attack databases by the way and now aware of them 186 00:07:59.239 --> 00:08:02.029 that it used to be but only remain as it's much harder to attack databases 187 00:08:02.029 --> 00:08:04.429 hard as long as we stay aware of the that it used to be but only remain as 188 00:08:04.429 --> 00:08:06.169 problem and we write our code hard as long as we stay aware of the 189 00:08:06.169 --> 00:08:07.039 accordingly problem and we write our code 190 00:08:07.039 --> 00:08:08.809 now this is all being a little bit accordingly 191 00:08:08.809 --> 00:08:10.999 contrived for one thing i had to change now this is all being a little bit 192 00:08:10.999 --> 00:08:13.339 our code to use the execute script contrived for one thing i had to change 193 00:08:13.339 --> 00:08:15.259 method came back to contacts 2. py our code to use the execute script 194 00:08:15.259 --> 00:08:17.869 method code on line 12 have to method came back to contacts 2. py 195 00:08:17.869 --> 00:08:20.419 change it to use execute script rather method code on line 12 have to 196 00:08:20.419 --> 00:08:22.159 than execute which you wouldn't normally change it to use execute script rather 197 00:08:22.159 --> 00:08:24.889 use when executing a query based on user than execute which you wouldn't normally 198 00:08:24.889 --> 00:08:27.559 input but i did that to demonstrate the use when executing a query based on user 199 00:08:27.559 --> 00:08:30.199 problem and to give a rough idea of what input but i did that to demonstrate the 200 00:08:30.199 --> 00:08:32.629 a sql injection attack is these problem and to give a rough idea of what 201 00:08:32.629 --> 00:08:34.699 days it's not a simple to perform an a sql injection attack is these 202 00:08:34.699 --> 00:08:36.829 injection attack but it's still days it's not a simple to perform an 203 00:08:36.829 --> 00:08:38.329 definitely possible injection attack but it's still 204 00:08:38.329 --> 00:08:39.860 you just need a deeper understanding of definitely possible 205 00:08:39.860 --> 00:08:40.910 sql you just need a deeper understanding of 206 00:08:40.910 --> 00:08:43.160 and your target database so let's actually sql 207 00:08:43.160 --> 00:08:45.890 see what happens if I change back and your target database so let's actually 208 00:08:45.890 --> 00:08:49.040 the execute script back to execute again see what happens if I change back 209 00:08:49.040 --> 00:08:54.680 here on line 12 if we run this again the execute script back to execute again 210 00:08:54.680 --> 00:08:56.000 bearing in mind that last time with the here on line 12 if we run this again 211 00:08:56.000 --> 00:08:58.850 execute script able to successfully bearing in mind that last time with the 212 00:08:58.850 --> 00:09:02.180 dropped the table so enter input execute script able to successfully 213 00:09:02.180 --> 00:09:03.410 1234 dropped the table so enter input 214 00:09:03.410 --> 00:09:08.900 ...we 1234 215 00:09:08.900 --> 00:09:11.000 actually get a warning this time you can ...we 216 00:09:11.000 --> 00:09:13.610 only execute one statement at a time so actually get a warning this time you can 217 00:09:13.610 --> 00:09:16.220 the python execute method is wise to only execute one statement at a time so 218 00:09:16.220 --> 00:09:17.840 this trick and won't actually allow the python execute method is wise to 219 00:09:17.840 --> 00:09:20.810 multiple statements to be executed but this trick and won't actually allow 220 00:09:20.810 --> 00:09:22.430 with that said we have crushed the program multiple statements to be executed but 221 00:09:22.430 --> 00:09:23.870 and that's not good with that said we have crushed the program 222 00:09:23.870 --> 00:09:26.090 alright so this is all leading up to and that's not good 223 00:09:26.090 --> 00:09:27.740 using placeholders and parameter alright so this is all leading up to 224 00:09:27.740 --> 00:09:29.450 substitutions so lets actually see how using placeholders and parameter 225 00:09:29.450 --> 00:09:32.030 both of those things can actually help substitutions so lets actually see how 226 00:09:32.030 --> 00:09:33.560 alright so first going to both of those things can actually help 227 00:09:33.560 --> 00:09:36.320 duplicate this line and i'm going to alright so first going to 228 00:09:36.320 --> 00:09:39.260 comment out the one the top line and duplicate this line and i'm going to 229 00:09:39.260 --> 00:09:41.660 going to change the line to update comment out the one the top line and 230 00:09:41.660 --> 00:09:46.130 contacts contacts... going to change the line to update 231 00:09:46.130 --> 00:09:48.320 ... contacts contacts... 232 00:09:48.320 --> 00:09:49.400 ... ... 233 00:09:49.400 --> 00:09:50.750 ...so we end up with a string ... 234 00:09:50.750 --> 00:09:52.820 like that and then we're going to come ...so we end up with a string 235 00:09:52.820 --> 00:09:54.740 down here to the update cursor . like that and then we're going to come 236 00:09:54.740 --> 00:09:56.930 execute method instead of just having down here to the update cursor . 237 00:09:56.930 --> 00:09:58.640 update SQL we're going to add two execute method instead of just having 238 00:09:58.640 --> 00:10:01.910 parameter here so... update SQL we're going to add two 239 00:10:01.910 --> 00:10:04.340 ... parameter here so... 240 00:10:04.340 --> 00:10:12.200 ... ... 241 00:10:12.200 --> 00:10:15.410 let's see whether that works ... 242 00:10:15.410 --> 00:10:17.090 first you must enter some valid input let's see whether that works 243 00:10:17.090 --> 00:10:19.100 1234 just to make sure that it does work first you must enter some valid input 244 00:10:19.100 --> 00:10:22.430 because we've got one row updating in 1234 just to make sure that it does work 245 00:10:22.430 --> 00:10:24.140 there and i'll just put up a little bit because we've got one row updating in 246 00:10:24.140 --> 00:10:25.340 higher so we can see that each time we there and i'll just put up a little bit 247 00:10:25.340 --> 00:10:27.710 run and the email has clearly been higher so we can see that each time we 248 00:10:27.710 --> 00:10:30.680 updated so that's working but let's try run and the email has clearly been 249 00:10:30.680 --> 00:10:32.840 running again and see if we can add an updated so that's working but let's try 250 00:10:32.840 --> 00:10:35.990 SQL injection attack again so 1234 running again and see if we can add an 251 00:10:35.990 --> 00:10:43.550 ....this time SQL injection attack again so 1234 252 00:10:43.550 --> 00:10:45.380 the program hasn't crashed we got these zeros ....this time 253 00:10:45.380 --> 00:10:47.750 updated and the Brian record hasn't the program hasn't crashed we got these zeros 254 00:10:47.750 --> 00:10:49.010 changed at all but the point is we updated and the Brian record hasn't 255 00:10:49.010 --> 00:10:51.440 haven't actually got an error here so changed at all but the point is we 256 00:10:51.440 --> 00:10:54.440 it's obviously something else going on haven't actually got an error here so 257 00:10:54.440 --> 00:10:56.210 when we use the parameter substitution it's obviously something else going on 258 00:10:56.210 --> 00:10:58.430 rather than manipulating the updates when we use the parameter substitution 259 00:10:58.430 --> 00:11:01.700 sql string so using placeholders which rather than manipulating the updates 260 00:11:01.700 --> 00:11:03.740 other question marks in a string on line sql string so using placeholders which 261 00:11:03.740 --> 00:11:07.130 9 and parameter substitution allows the other question marks in a string on line 262 00:11:07.130 --> 00:11:08.570 python sql light library to 9 and parameter substitution allows the 263 00:11:08.570 --> 00:11:11.000 sanitize the input so that means it python sql light library to 264 00:11:11.000 --> 00:11:12.440 will check for things like additional sanitize the input so that means it 265 00:11:12.440 --> 00:11:14.570 sql statements that an attacker has will check for things like additional 266 00:11:14.570 --> 00:11:17.210 tried to execute now there is a lot more sql statements that an attacker has 267 00:11:17.210 --> 00:11:19.250 to it than that and sanitizing the tried to execute now there is a lot more 268 00:11:19.250 --> 00:11:21.380 input is quite complex to it than that and sanitizing the 269 00:11:21.380 --> 00:11:23.360 luckily we don't have to worry too much input is quite complex 270 00:11:23.360 --> 00:11:25.730 about that and if you are writing a luckily we don't have to worry too much 271 00:11:25.730 --> 00:11:27.260 database library like the sqlite about that and if you are writing a 272 00:11:27.260 --> 00:11:29.330 three module then obviously it's database library like the sqlite 273 00:11:29.330 --> 00:11:30.920 something you have to fully understand three module then obviously it's 274 00:11:30.920 --> 00:11:33.260 but in our case for our purposes it's something you have to fully understand 275 00:11:33.260 --> 00:11:34.880 enough to know that using placeholders but in our case for our purposes it's 276 00:11:34.880 --> 00:11:37.010 rather than building up sql strings enough to know that using placeholders 277 00:11:37.010 --> 00:11:40.400 ourselves is much safer so all the hard rather than building up sql strings 278 00:11:40.400 --> 00:11:42.560 works been done by the programmers who ourselves is much safer so all the hard 279 00:11:42.560 --> 00:11:44.900 created a sqlite three module and works been done by the programmers who 280 00:11:44.900 --> 00:11:46.640 all we have to do is remember never to created a sqlite three module and 281 00:11:46.640 --> 00:11:48.530 build up a single string using any all we have to do is remember never to 282 00:11:48.530 --> 00:11:50.570 values that may have come from outside build up a single string using any 283 00:11:50.570 --> 00:11:52.820 our program now it's perfectly values that may have come from outside 284 00:11:52.820 --> 00:11:55.070 acceptable to use string formatting to our program now it's perfectly 285 00:11:55.070 --> 00:11:56.720 provide table and column names from acceptable to use string formatting to 286 00:11:56.720 --> 00:11:58.610 constant stored in our code for example provide table and column names from 287 00:11:58.610 --> 00:12:01.520 but never do that if the values may have constant stored in our code for example 288 00:12:01.520 --> 00:12:04.130 come from user input or from parameters but never do that if the values may have 289 00:12:04.130 --> 00:12:06.620 passed to your functions from external come from user input or from parameters 290 00:12:06.620 --> 00:12:08.060 code passed to your functions from external 291 00:12:08.060 --> 00:12:09.140 alright I'm going to finish the video code 292 00:12:09.140 --> 00:12:11.090 here in the next one we're going to go alright I'm going to finish the video 293 00:12:11.090 --> 00:12:14.000 on and start looking at how we actually here in the next one we're going to go 294 00:12:14.000 --> 00:12:15.590 use placeholders because we've talked on and start looking at how we actually 295 00:12:15.590 --> 00:12:17.570 about the problem they are designed to solve use placeholders because we've talked 296 00:12:17.570 --> 00:12:20.300 but let's actually move on to looking at about the problem they are designed to solve 297 00:12:20.300 --> 00:12:21.350 them in more detail but let's actually move on to looking at 298 00:12:21.350 --> 00:12:27.250 see you in the next video them in more detail