Path: csiph.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail From: Arno Welzel Newsgroups: comp.lang.php Subject: Re: PHP processing steps to apply to a URL to make it safe Date: Wed, 17 Feb 2016 15:47:22 +0100 Lines: 26 Message-ID: <56C487FA.1070401@arnowelzel.de> References: <56c47913$0$24153$e4fe514c@news.xs4all.nl> <56C47E05.10508@arnowelzel.de> <56c48103$0$24054$e4fe514c@news.xs4all.nl> Mime-Version: 1.0 Content-Type: text/plain; charset=iso-8859-15 Content-Transfer-Encoding: 7bit X-Trace: individual.net oGOR71fNNFRywxP//6TcBgSynW4hpnLH4t0fqWGU5Ynlr25OpV Cancel-Lock: sha1:RDNO7bx36gtS2xsTRMOhtC2EDXI= In-Reply-To: <56c48103$0$24054$e4fe514c@news.xs4all.nl> Xref: csiph.com comp.lang.php:16447 R.Wieser schrieb am 2016-02-17 um 15:17: > Arno, > >> And what do SQL injections have to do with "safe URL"? > > Please step away from the computer *now*. Bring it back to where you bought > it and ask your money back. > > In other words: Either you are trolling, or you should not be doing anything > with PHP. How does an *URL* itself cause an SQL injection? At least a PHP script has to use the provided values and use it within an SQL statement. And maybe you should also see my other post <56C445F6.1090008@arnowelzel.de> which I just sent a couple hours ago (before your post) where I refer to possible security risks - including SQL injection. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de http://fahrradzukunft.de