Re: [off] PHP: a fractal of bad design
| From: | Lester Caine | Date: | Wed, 11 Apr 2012 08:29:28 +0000 |
| Subject: | Re: [off] PHP: a fractal of bad design | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-59728@lists.php.net to get a copy of this message | ||
Yasuo Ohgaki wrote:
Anyway, http://www.php.net/manual/en/security.database.sql-injection.php I've never read this page. This page must be improved...That is almost archaic it's self ... It should be replaced with a pointer to using parameters ( no we do not need 'prepared statements', just parameters ). One of the first things I implement on any code that I'm porting. Does away with any agro over escaping strings and is totally save 'injection' wise. -- Lester Caine - G8HFL ----------------------------- Contact - http://lsces.co.uk/wiki/?page=contact L.S.Caine Electronic Services - http://lsces.co.uk EnquirySolve - http://enquirysolve.com/ Model Engineers Digital Workshop - http://medw.co.uk// Firebird - http://www.firebirdsql.org/index.php