note 114045 added to function.intval
| From: | jplevene at netscape dot net | Date: | Mon, 06 Jan 2014 11:40:47 +0000 |
| Subject: | note 114045 added to function.intval | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-198123@lists.php.net to get a copy of this message | ||
I have found intval very useful for database security.
If you are passing a value via
- Data from user input
- Data that you have stored RAW on DB (witch is the best way) and you are using on a new sql
statment
- Data from unknown/other origin
and the data is supposed to be an integer, I always run it through intval before I put it into the
query (or you could use real_escape_string)
This prevents hackers from passing the variable as an SQL statement instead of a number in order to
attack your database.
----
Server IP: 87.117.229.81
Probable Submitter: 92.26.83.112
----
Manual Page -- http://php.net/manual/en/function.intval.php
Edit -- https://master.php.net/note/edit/114045
Del: integrated -- https://master.php.net/note/delete/114045/integrated
Del: useless -- https://master.php.net/note/delete/114045/useless
Del: bad code -- https://master.php.net/note/delete/114045/bad+code
Del: spam -- https://master.php.net/note/delete/114045/spam
Del: non-english -- https://master.php.net/note/delete/114045/non-english
Del: in docs -- https://master.php.net/note/delete/114045/in+docs
Del: other reasons-- https://master.php.net/note/delete/114045
Reject -- https://master.php.net/note/reject/114045
Search -- https://master.php.net/manage/user-notes.php