Re: addslahes and magic quote woes
| From: | Erik Price | Date: | Wed, 03 Jul 2002 14:55:49 +0000 |
| Subject: | Re: addslahes and magic quote woes | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-105209@lists.php.net to get a copy of this message | ||
On Wednesday, July 3, 2002, at 10:21 AM, Jean-Christian Imbeault wrote:
Security question: Is turning off magic_quotes and using strip/addslashes() a 100% effective solution against malicious user input?No. Think about what {add|strip}slashes() does. It simply adds slashes to strings, and strips them from strings, depending on certain rules (like the location of apostrophes or other special characters in those strings). There are far more ways for malicious users to insert their own input than I even know of, let alone know how to handle. Consider using add/strip a requirement, not a security precaution. Erik ---- Erik Price Web Developer Temp Media Lab, H.H. Brown pricee@hhbrown.com