Re: Addslashes?

From: Date: Fri, 29 Sep 2000 09:50:28 +0000
Subject: Re: Addslashes?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-18025@lists.php.net to get a copy of this message
As I understand it, addslashes() is not really about security, it is about preventing quotes in input from stuffing up MySQL, which doesn't like them (or rather, interprets them as something else). to find and remove special characters in variables that could be used for nefarious purposes, use ereg() and/or ereg_replace(). another useful function is quotemeta(). All this stuff is in the manual. Michael Hall ----- Original Message ----- From: Chris <php_list@ibcnetwork.net> To: php <php-general@lists.php.net> Sent: Friday, September 29, 2000 1:40 AM Subject: [PHP] Addslashes? Hi, I have a question about security. Say I have a form that takes a users input, then I use that to select or insert data into a mysql table. What all should be done to that inputed value before acually using it? Is addslashes() good enough? Are there some special characters that should never be allowed to stay in the variable? Help please, Thanks Chris

« previous php.general (#18025) next »