Re: $$vars and security
| From: | Phillip Jackson | Date: | Tue, 25 Nov 2003 10:03:04 +0000 |
| Subject: | Re: $$vars and security | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-170863@lists.php.net to get a copy of this message | ||
> Personally, I think this is a bad approach, regardless of how well it is
> implemented. I think you will give yourself a false sense of security.
what, then, do you yourself do in such an application requiring a response
from the user to massage the data? reject all input that doesn't conform to
your whitelist? i shall look into making this the vital part of the escape
function.
> Hope that helps.
most definitely - thank you for the quick response.