Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #4204

Re: BB type posting - is this secure?

From "M. Strobel" <sorry_no_mail_here@nowhere.dee>
Newsgroups comp.lang.php
Subject Re: BB type posting - is this secure?
Date 2012-01-01 19:20 +0100
Message-ID <9mbmf3FnpqU1@mid.uni-berlin.de> (permalink)
References <ptqpf75jh2fra5qfu8jhum3bn4ug6r17ot@4ax.com> <jdk22d$l9p$1@dont-email.me> <c6krf7l6t9mni7ql4nkua2c53kspied1g0@4ax.com> <jdl7j1$i4u$1@gregory.bnet.hr>

Show all headers | View raw


> so here is how you filter input data:
> 
> 1. use filter_var or other method of removing any unwanted input (for 
> example if you expect a number then filter out any other characters except 
> 0123456789, easily done with filter_var)
> 2. use pdo / parametrized statements to insert data into database for 
> additional security and to avoid sql injection
> 3. when displaying this data back on console use htmlentities to correcly 
> print < > into &lt; &gt; etc.
> 
> and that is all there is to it.

This is it: on input to script, on input to database, and on
output to browser. I might add to

1. use your own filter function on form input, in case you have
to adjust it. A length limit on input strings might be useful.

3. If you use Smarty (or the like) you do it in your template,
and don't clutter your code.

/Str.

Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-29 17:45 -0500
  Re: BB type posting - is this secure? "A" <a@a.a> - 2011-12-30 00:14 +0100
  Re: BB type posting - is this secure? Curtis Dyer <dyer85@gmail.com> - 2011-12-29 23:29 +0000
    Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-29 23:27 -0500
      Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-30 00:29 -0500
        Re: BB type posting - is this secure? Jerry Stuckle <jstucklex@attglobal.net> - 2011-12-30 05:59 -0500
  Re: BB type posting - is this secure? "Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid> - 2011-12-30 10:59 +0100
    Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-30 10:01 -0500
      Re: BB type posting - is this secure? Michael Fesser <netizen@gmx.de> - 2011-12-30 19:14 +0100
      Re: BB type posting - is this secure? "A" <a@a.a> - 2011-12-30 21:39 +0100
        Re: BB type posting - is this secure? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-01 19:20 +0100
      Re: BB type posting - is this secure? Curtis Dyer <dyer85@gmail.com> - 2012-01-04 07:24 +0000

csiph-web