Jump to content

help: secure input


delickate

Recommended Posts

thanks for the reply,

what is PDO? can u give me an example of that?

e.g:

if we code for mysql_real_escape_string()  like this

echo "insert into table(feidlname) values('".mysql_real_escape_string($value) ."')";

 

how would we do code for PDO?

like this

echo "insert into table(feidlname) values('".PDO($value) ."')";

 

please guide

thanks

Link to comment
Share on other sites

You'll also want to validate / sanitize the data, if you haven't done so already. For example, if a field is supposed to be a number, you could check by using something like ctype_digit():

 

<?php
if( ctype_digit( (string) $numToTest) ) {
     print "Number; continue processing";
} else {
     print "Not a number; flag error";
}
?>

 

 

If selecting one of several radio buttons in a form, make sure the value corresponds with one of the options.

 

If the value isn't supposed to contain HTML / PHP tags, you could run strip_tags() to remove them.

http://php.net/manual/en/function.strip-tags.php

Link to comment
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.