note 32490 added to security.database
| From: | thesibster at hotmail dot com | Date: | Wed, 28 May 2003 23:49:51 +0000 |
| Subject: | note 32490 added to security.database | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-49219@lists.php.net to get a copy of this message | ||
Note that if a semicolon (;) or double hyphen (--) appears within a string, it is not dangerous to
queries. Addslashes() forces the user input not to terminate a string, so as long as you enclose
the validated user input in a string, there's no danger with those particular two bits of
syntax.
On a completely different note, I think yet another good way to secure passwords, etc. from being
readable by someone with access to the server is to place them in functions in compiled files so
that they are not just plain text. This works with Java classes, and I imagine it works with COM
and .NET as well. My only problem with this is that the Java to PHP interaction and the .NET
functionality are not yet solidly defined, and COM doesn't work under anything but Windows.
I'd appreciate it if someone would post a way better than Java to do this on a non-Windows
system.
----
Manual Page -- http://www.php.net/manual/en/security.database.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+32490
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+32490&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+32490&report=yes