Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #4202
| From | "A" <a@a.a> |
|---|---|
| Newsgroups | comp.lang.php |
| Subject | Re: BB type posting - is this secure? |
| Date | 2011-12-30 21:39 +0100 |
| Organization | B.net Hrvatska d.o.o. |
| Message-ID | <jdl7j1$i4u$1@gregory.bnet.hr> (permalink) |
| References | <ptqpf75jh2fra5qfu8jhum3bn4ug6r17ot@4ax.com> <jdk22d$l9p$1@dont-email.me> <c6krf7l6t9mni7ql4nkua2c53kspied1g0@4ax.com> |
"Michael Joel" <no@please.com> wrote in message news:c6krf7l6t9mni7ql4nkua2c53kspied1g0@4ax.com... > stripslashes is used as it comes out of the db, addslashes are used as > it goes in (but as mention mysql_real_escape_string is to be used). just forget about strip/addslashes. use parametrized statements. it is really easy and you won't have to think about tons of things. it took me ages to switch to them, never looked back since as it is just so much easier. when you use parametrized statements then on every ? or :param: it replaces it with raw data. it doesn't care whether you are inserting single quote or backslash. it just inserts it as raw data. also, parametrized statements are FASTER. you don't have to convert strings from one format to another, escape them etc., you just insert them. database engine doesn't need to prepare virtual machine for parsing queries, again it is faster, especially if you use SQLite. and finally, it is safe agains first level of sql injection attacks (data to database). and also use PDO. again, so much easier it does tons of things for you. so here is how you filter input data: 1. use filter_var or other method of removing any unwanted input (for example if you expect a number then filter out any other characters except 0123456789, easily done with filter_var) 2. use pdo / parametrized statements to insert data into database for additional security and to avoid sql injection 3. when displaying this data back on console use htmlentities to correcly print < > into < > etc. and that is all there is to it.
Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-29 17:45 -0500
Re: BB type posting - is this secure? "A" <a@a.a> - 2011-12-30 00:14 +0100
Re: BB type posting - is this secure? Curtis Dyer <dyer85@gmail.com> - 2011-12-29 23:29 +0000
Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-29 23:27 -0500
Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-30 00:29 -0500
Re: BB type posting - is this secure? Jerry Stuckle <jstucklex@attglobal.net> - 2011-12-30 05:59 -0500
Re: BB type posting - is this secure? "Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid> - 2011-12-30 10:59 +0100
Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-30 10:01 -0500
Re: BB type posting - is this secure? Michael Fesser <netizen@gmx.de> - 2011-12-30 19:14 +0100
Re: BB type posting - is this secure? "A" <a@a.a> - 2011-12-30 21:39 +0100
Re: BB type posting - is this secure? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-01 19:20 +0100
Re: BB type posting - is this secure? Curtis Dyer <dyer85@gmail.com> - 2012-01-04 07:24 +0000
csiph-web