Re: $$vars and security

From: Date: Tue, 25 Nov 2003 10:03:04 +0000
Subject: Re: $$vars and security
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-170863@lists.php.net to get a copy of this message
> Personally, I think this is a bad approach, regardless of how well it is > implemented. I think you will give yourself a false sense of security. what, then, do you yourself do in such an application requiring a response from the user to massage the data? reject all input that doesn't conform to your whitelist? i shall look into making this the vital part of the escape function. > Hope that helps. most definitely - thank you for the quick response.

« previous php.general (#170863) next »