Re: Sterilize user input function
| From: | B. van Ouwerkerk | Date: | Sat, 08 Sep 2001 19:56:59 +0000 |
| Subject: | Re: Sterilize user input function | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-66543@lists.php.net to get a copy of this message | ||
For emails I've seen some nice work somewhere in the annoted manual.
I think it's in the chapter about regular expressions..
http://www.php.net/manual/en/function.ereg.php
You might not only want to kill anything dangerous.. Checking email address is also handy to prevent your database to be filled with crap..
For Phone numbers you could create a page which contains the - between the numbers.. so only numbers are allowed.. quite easy with regular expressions..
Or just one filed and check the number someone gives and see if it hold the string you thought it should hold.
Think about what you want to allow and what you want to refuse.
Bye,
B.
At 11:27 8-9-01 -0600, Kevin wrote:
I am looking for general a function to that would render user input harmless. I would write my own but don't know what to strip from the input that could make it potentially damaging on linux boxes. I need to accept email and phone numbers. Thanks in advance, Kevin -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net