note 26097 added to security.database
| From: | thelogrus at yahoo dot se | Date: | Thu, 17 Oct 2002 22:37:33 +0000 |
| Subject: | note 26097 added to security.database | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-38222@lists.php.net to get a copy of this message | ||
Greetings.
Well I'm coding a bit and I had no idea about this for exampel:
Login: admin
Password:' or '1==1
Very rude way of telling me he had, well anyways. I quickly went here and foraged around.
I started with
$_POST['var']=addslashes...
for each post that the scripts needed to handle. well that is...quite ineffective so I wrote this:
function checkpost($PF){
$PF2=$PF; //Cant change the foreach $PF values it seems, no good. Think I read something about it.
Fix.
foreach($PF as $key =>$v){
$t=substr($key,0,1);
if( $t=="S"){
$PF2[$key] = addslashes($PF2[$key]);
}
elseif($t=="I"){
$PF2[$key]=intval($PF2[$key]);
}
elseif($t=="F"){
$PF2[$key]=floatval($PF2[$key]);
}
else{
$PF2[$key] = addslashes($PF2[$key]);
}
}
return $PF2; //Return the post. and live happily ever after.
}
$_POST=checkpost($_POST);
----
Now it rests upon naming the diffrent fields. for instance
<input type="text" name="Spassword">
Three diffrent types are defined
A field that should contain a string
starts with S
an integer with I and floating with F.
Then the function goes through the post
and returns a checked one. Hopefully.
It might be usefull I guess so I post it here.
Happy Coding.
/Charlie, Coding is like being a sheperd.
--
http://www.php.net/manual/en/security.database.php
http://master.php.net/manage/user-notes.php?action=edit+26097
http://master.php.net/manage/user-notes.php?action=delete+26097
http://master.php.net/manage/user-notes.php?action=reject+26097