Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #4201

Re: BB type posting - is this secure?

From Michael Fesser <netizen@gmx.de>
Newsgroups comp.lang.php
Subject Re: BB type posting - is this secure?
Date 2011-12-30 19:14 +0100
Message-ID <1jvrf7lsba3bcfef9ljmap75v3iv8vhhci@mfesser.de> (permalink)
References <ptqpf75jh2fra5qfu8jhum3bn4ug6r17ot@4ax.com> <jdk22d$l9p$1@dont-email.me> <c6krf7l6t9mni7ql4nkua2c53kspied1g0@4ax.com>

Show all headers | View raw


.oO(Michael Joel)

>Sorry I did not make it clear.
>
>stripslashes is used as it comes out of the db

This will corrupt your data!

Think of adding slashes just as a way to "mark" some chars, so that the
DB doesn't interpret them. It's not about adding literal slashes to your
strings, so you don't have to remove anything after retrieving the data
from the DB.

In other words: Adding slashes doesn't change your string data, it just
ensures that all chars, even the special ones, make it into the DB as
they are.

>, addslashes are used as
>it goes in (but as mention mysql_real_escape_string is to be used).

Good. You could also have a look at prepared statements.

Micha

-- 
http://mfesser.de/blickwinkel

Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-29 17:45 -0500
  Re: BB type posting - is this secure? "A" <a@a.a> - 2011-12-30 00:14 +0100
  Re: BB type posting - is this secure? Curtis Dyer <dyer85@gmail.com> - 2011-12-29 23:29 +0000
    Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-29 23:27 -0500
      Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-30 00:29 -0500
        Re: BB type posting - is this secure? Jerry Stuckle <jstucklex@attglobal.net> - 2011-12-30 05:59 -0500
  Re: BB type posting - is this secure? "Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid> - 2011-12-30 10:59 +0100
    Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-30 10:01 -0500
      Re: BB type posting - is this secure? Michael Fesser <netizen@gmx.de> - 2011-12-30 19:14 +0100
      Re: BB type posting - is this secure? "A" <a@a.a> - 2011-12-30 21:39 +0100
        Re: BB type posting - is this secure? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-01 19:20 +0100
      Re: BB type posting - is this secure? Curtis Dyer <dyer85@gmail.com> - 2012-01-04 07:24 +0000

csiph-web