Jump to content

how to escape the hacking input


phpmady

Recommended Posts

Hi,

 

when i submit the form using the following text...

 

-1 OR 1=1) AND 1=(SELECT IF((IFNULL(ASCII(SUBSTRING((SELECT @@VERSION),1,1)),0)>25),1,2))

 

that was sent by the hacker in my website

 

i am trying to escape the above and filter it ...

 

 

am using the mysql_Real_escape_string and trim function..

 

but nothing escaped...

 

can u give me a suggestion , pls help me

Link to comment
https://forums.phpfreaks.com/topic/213918-how-to-escape-the-hacking-input/
Share on other sites

Try the link in my signature follow all 4 courses : )

 

 

Thanks,

 

as u said i use the following function to

 

function make_safe($variable) {

 

 

    $variable = mysql_real_escape_string(trim($variable));

 

 

    return $variable;

}

 

 

but nothing escapes

 

 

 

mysql_real_escape_string(), as its name implies, is only useful for escaping string data (data that is in between single-quotes in your query.)

 

For numeric data, you must either validate that it is numeric or cast it as a number.

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.