Re: form security problem
| From: | Daniel Convissor | Date: | Wed, 11 Oct 2000 18:17:35 +0000 |
| Subject: | Re: form security problem | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-19657@lists.php.net to get a copy of this message | ||
Hey Vojtìch:
> (input name="test" type="text" value="0")
> ... snip ...
> The problem is that anybody can save this page on
> his computer and edit the value="xx" and then send
> it to my DB.
You are SO correct, congratulations. As you realize, one should NEVER TRUST
USER INPUT.
There are several ways to handle the situation, depending on what values
you're expecting:
Remove all non numeric characters:
$test = ereg_replace("[^0-9]", "", $test);
Perhaps, then ensure there's something there at all:
if ( !strlen($test) ) {
echo "HEY, you've got to enter something...";
exit();
}
Or, ensure the value is within an acceptable range:
if ($test > 10) {
echo "HEY, you entered something too large...";
exit();
}
In the tests, you alternately can complain and then reprint the input form
then exit or you can just set the value to 0 or something like that. All
depends what your goal is.
I trust you get the idea.
Enjoy,
--Dan
--
T H E A N A L Y S I S A N D S O L U T I O N S C O M P A N Y
More than just answers. Solutions. (SM)
http://www.analysisandsolutions.com/
4015 7 Av #4, Brooklyn NY 11232 v: 718-854-0335 f: 718-854-0409