Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!aioe.org!eternal-september.org!feeder.eternal-september.org!mx04.eternal-september.org!.POSTED!not-for-mail From: Arno Welzel Newsgroups: comp.lang.php Subject: Re: Magic quotes? Should I still be cautious? Date: Thu, 05 Jan 2012 14:22:25 +0100 Organization: A noiseless patient Spider Lines: 41 Message-ID: <4F05A411.7000009@arnowelzel.de> References: <4F046877.3080409@arnowelzel.de> <4f05a0b4$0$6924$e4fe514c@news2.news.xs4all.nl> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Injection-Info: mx04.eternal-september.org; posting-host="dd4uQGf4fHOQcq7/hg1u1Q"; logging-data="32705"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19QQ7uliGfs5wfd+dQLxU4Tkqfc838l/UI=" User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20111105 Thunderbird/8.0 In-Reply-To: <4f05a0b4$0$6924$e4fe514c@news2.news.xs4all.nl> Cancel-Lock: sha1:i7LxXYmwypLHoY619PyuZ5S1XVA= Xref: x330-a1.tempe.blueboxinc.net comp.lang.php:4221 Erwin Moller, 2012-01-05 14:08: > On 1/4/2012 3:55 PM, Arno Welzel wrote: >> Michael Joel, 2011-12-29 21:55: >> >>> I do not have control of my server (shared server). >>> >>> echo get_magic_quotes_gpc(); returns True. >>> Should I still be cautious and use addslashes/stripslashes in case the >>> hosting company ever decides to change the settings? >> >> I assume magic quotes to be disabled and in the past i used the >> following code fragment to be safe: >> >> >> >> > > Hi Arnold, Just Arno - not Arnold ;-) > That is a lot of overhead on each request. I know - and this is only meant to be a workaround for existing code which can not be easily adopted to handle Magic Quotes and the PHP configuration can not be changed. > And $_REQUEST should be avoided anyway in all situation (in my humble > opinion) for various reasons. But if you use it, it should indeed be > added to your list in your approach. I'm not sure, if it's enough to modify $_GET, $_POST etc. if further parts of a script use $_REQUEST - therefore i added $_REQUEST to be sure. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de