Jump to content

Recommended Posts

Hi,

 

when i submit the form using the following text...

 

-1 OR 1=1) AND 1=(SELECT IF((IFNULL(ASCII(SUBSTRING((SELECT @@VERSION),1,1)),0)>25),1,2))

 

that was sent by the hacker in my website

 

i am trying to escape the above and filter it ...

 

 

am using the mysql_Real_escape_string and trim function..

 

but nothing escaped...

 

can u give me a suggestion , pls help me

Link to comment
https://forums.phpfreaks.com/topic/213918-how-to-escape-the-hacking-input/
Share on other sites

Try the link in my signature follow all 4 courses : )

 

 

Thanks,

 

as u said i use the following function to

 

function make_safe($variable) {

 

 

    $variable = mysql_real_escape_string(trim($variable));

 

 

    return $variable;

}

 

 

but nothing escapes

 

 

 

mysql_real_escape_string(), as its name implies, is only useful for escaping string data (data that is in between single-quotes in your query.)

 

For numeric data, you must either validate that it is numeric or cast it as a number.

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.