Jump to content

Recommended Posts

Hey guys,

 

Just made my login page, but i am worried about people putting code in their usernames or when they enter anything into an input in a form. How can i combat this? i have already made the fields all lowercase to make my life easier in the database.

 

Striptags? or go further?

 

Thanks,

Joel

i assume your talking about SQL injection.. or XSS..

 

$username = addslashes($_POST['username']);
$sql = "select * from USERS where username = $username";

 

$usermessage = htmlentities(POST['message']);
echo $usermessage;

 

if that doesn't help, please post more detail..

 

 

Ok thanks for the replies, i am going to use all of these to create a function for every input field. But, i need a function where you can specify characters that are disallowed for example "_". I think maybe using a preg match to detect illegal characters and throw up and error.

 

Thanks,

 

Joel

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.