note 48604 deleted from function.mysql-real-escape-string by aidan
| From: | aidan@php.net | Date: | Sun, 24 May 2009 19:48:43 +0000 |
| Subject: | note 48604 deleted from function.mysql-real-escape-string by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-155942@lists.php.net to get a copy of this message | ||
Note Submitter: ludvig dot ericson at gmail dot com
----
A case where you do not need to escape is when you are about to compare the UI (User Input) with a
database through MD5 hashes, infact if you do, the password stored in the database will not match
the one in the request.
I had a living hell trying to solve this in my earlier days, so I just wanted to enligthen any
other newbies,
<?php
$try_pass=md5($_POST['u_pass']);
?>
is sufficient escaping.
Cheers