Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #4202

Re: BB type posting - is this secure?

From "A" <a@a.a>
Newsgroups comp.lang.php
Subject Re: BB type posting - is this secure?
Date 2011-12-30 21:39 +0100
Organization B.net Hrvatska d.o.o.
Message-ID <jdl7j1$i4u$1@gregory.bnet.hr> (permalink)
References <ptqpf75jh2fra5qfu8jhum3bn4ug6r17ot@4ax.com> <jdk22d$l9p$1@dont-email.me> <c6krf7l6t9mni7ql4nkua2c53kspied1g0@4ax.com>

Show all headers | View raw


"Michael Joel" <no@please.com> wrote in message 
news:c6krf7l6t9mni7ql4nkua2c53kspied1g0@4ax.com...
> stripslashes is used as it comes out of the db, addslashes are used as
> it goes in (but as mention mysql_real_escape_string is to be used).

just forget about strip/addslashes. use parametrized statements. it is 
really easy and you won't have to think about tons of things.
it took me ages to switch to them, never looked back since as it is just so 
much easier.

when you use parametrized statements then on every ? or :param: it replaces 
it with raw data. it doesn't care whether you are inserting single quote or 
backslash. it just inserts it as raw data.
also, parametrized statements are FASTER. you don't have to convert strings 
from one format to another, escape them etc., you just insert them. database 
engine doesn't need to prepare virtual machine for parsing queries, again it 
is faster, especially if you use SQLite.

and finally, it is safe agains first level of sql injection attacks (data to 
database).

and also use PDO. again, so much easier it does tons of things for you.

so here is how you filter input data:

1. use filter_var or other method of removing any unwanted input (for 
example if you expect a number then filter out any other characters except 
0123456789, easily done with filter_var)
2. use pdo / parametrized statements to insert data into database for 
additional security and to avoid sql injection
3. when displaying this data back on console use htmlentities to correcly 
print < > into &lt; &gt; etc.

and that is all there is to it.

Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-29 17:45 -0500
  Re: BB type posting - is this secure? "A" <a@a.a> - 2011-12-30 00:14 +0100
  Re: BB type posting - is this secure? Curtis Dyer <dyer85@gmail.com> - 2011-12-29 23:29 +0000
    Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-29 23:27 -0500
      Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-30 00:29 -0500
        Re: BB type posting - is this secure? Jerry Stuckle <jstucklex@attglobal.net> - 2011-12-30 05:59 -0500
  Re: BB type posting - is this secure? "Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid> - 2011-12-30 10:59 +0100
    Re: BB type posting - is this secure? Michael Joel <no@please.com> - 2011-12-30 10:01 -0500
      Re: BB type posting - is this secure? Michael Fesser <netizen@gmx.de> - 2011-12-30 19:14 +0100
      Re: BB type posting - is this secure? "A" <a@a.a> - 2011-12-30 21:39 +0100
        Re: BB type posting - is this secure? "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-01 19:20 +0100
      Re: BB type posting - is this secure? Curtis Dyer <dyer85@gmail.com> - 2012-01-04 07:24 +0000

csiph-web