Jump to content

Protection against people entering code in inputs


JoelRocks

Recommended Posts

Hey guys,

 

Just made my login page, but i am worried about people putting code in their usernames or when they enter anything into an input in a form. How can i combat this? i have already made the fields all lowercase to make my life easier in the database.

 

Striptags? or go further?

 

Thanks,

Joel

i assume your talking about SQL injection.. or XSS..

 

$username = addslashes($_POST['username']);
$sql = "select * from USERS where username = $username";

 

$usermessage = htmlentities(POST['message']);
echo $usermessage;

 

if that doesn't help, please post more detail..

 

 

Ok thanks for the replies, i am going to use all of these to create a function for every input field. But, i need a function where you can specify characters that are disallowed for example "_". I think maybe using a preg match to detect illegal characters and throw up and error.

 

Thanks,

 

Joel

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.