Re: addslahes and magic quote woes
| From: | Jean-Christian Imbeault | Date: | Wed, 03 Jul 2002 14:21:37 +0000 |
| Subject: | Re: addslahes and magic quote woes | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-105195@lists.php.net to get a copy of this message | ||
Erik Price wrote:
Turn off magic_quotes and do addslashes() explicitly every time you do a database insert. Then make sure you always stripslash() data returned from a database query. magic_quotes is convenient for newbies, but after a while you'll find it only trips you up, as you've discovered.I totally agree. Security question: Is turning off magic_quotes and using strip/addslashes() a 100% effective solution against malicious user input? Jc