Re: addslahes and magic quote woes

From: Date: Wed, 03 Jul 2002 14:21:37 +0000
Subject: Re: addslahes and magic quote woes
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-105195@lists.php.net to get a copy of this message
Erik Price wrote:
Turn off magic_quotes and do addslashes() explicitly every time you do a database insert. Then make sure you always stripslash() data returned from a database query. magic_quotes is convenient for newbies, but after a while you'll find it only trips you up, as you've discovered.
I totally agree. Security question: Is turning off magic_quotes and using strip/addslashes() a 100% effective solution against malicious user input? Jc

« previous php.general (#105195) next »