Re: form security problem

From: Date: Wed, 11 Oct 2000 18:17:35 +0000
Subject: Re: form security problem
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-19657@lists.php.net to get a copy of this message
Hey Vojtìch: > (input name="test" type="text" value="0") > ... snip ... > The problem is that anybody can save this page on > his computer and edit the value="xx" and then send > it to my DB. You are SO correct, congratulations. As you realize, one should NEVER TRUST USER INPUT. There are several ways to handle the situation, depending on what values you're expecting: Remove all non numeric characters: $test = ereg_replace("[^0-9]", "", $test); Perhaps, then ensure there's something there at all: if ( !strlen($test) ) { echo "HEY, you've got to enter something..."; exit(); } Or, ensure the value is within an acceptable range: if ($test > 10) { echo "HEY, you entered something too large..."; exit(); } In the tests, you alternately can complain and then reprint the input form then exit or you can just set the value to 0 or something like that. All depends what your goal is. I trust you get the idea. Enjoy, --Dan -- T H E A N A L Y S I S A N D S O L U T I O N S C O M P A N Y More than just answers. Solutions. (SM) http://www.analysisandsolutions.com/ 4015 7 Av #4, Brooklyn NY 11232 v: 718-854-0335 f: 718-854-0409

« previous php.general (#19657) next »