Jump to content

help: secure input


delickate

Recommended Posts

thanks for the reply,

what is PDO? can u give me an example of that?

e.g:

if we code for mysql_real_escape_string()  like this

echo "insert into table(feidlname) values('".mysql_real_escape_string($value) ."')";

 

how would we do code for PDO?

like this

echo "insert into table(feidlname) values('".PDO($value) ."')";

 

please guide

thanks

Link to comment
https://forums.phpfreaks.com/topic/257153-help-secure-input/#findComment-1318223
Share on other sites

You'll also want to validate / sanitize the data, if you haven't done so already. For example, if a field is supposed to be a number, you could check by using something like ctype_digit():

 

<?php
if( ctype_digit( (string) $numToTest) ) {
     print "Number; continue processing";
} else {
     print "Not a number; flag error";
}
?>

 

 

If selecting one of several radio buttons in a form, make sure the value corresponds with one of the options.

 

If the value isn't supposed to contain HTML / PHP tags, you could run strip_tags() to remove them.

http://php.net/manual/en/function.strip-tags.php

Link to comment
https://forums.phpfreaks.com/topic/257153-help-secure-input/#findComment-1318342
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.