Re: addslahes and magic quote woes

From: Date: Wed, 03 Jul 2002 14:55:49 +0000
Subject: Re: addslahes and magic quote woes
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-105209@lists.php.net to get a copy of this message
On Wednesday, July 3, 2002, at 10:21 AM, Jean-Christian Imbeault wrote:
Security question: Is turning off magic_quotes and using strip/addslashes() a 100% effective solution against malicious user input?
No. Think about what {add|strip}slashes() does. It simply adds slashes to strings, and strips them from strings, depending on certain rules (like the location of apostrophes or other special characters in those strings). There are far more ways for malicious users to insert their own input than I even know of, let alone know how to handle. Consider using add/strip a requirement, not a security precaution. Erik ---- Erik Price Web Developer Temp Media Lab, H.H. Brown pricee@hhbrown.com

« previous php.general (#105209) next »