note 32490 deleted from security.database by didou
| From: | didou@php.net | Date: | Sat, 07 Feb 2004 15:16:52 +0000 |
| Subject: | note 32490 deleted from security.database by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-64772@lists.php.net to get a copy of this message | ||
Note Submitter: thesibster@hotmail.com
----
Note that if a semicolon (;) or double hyphen (--) appears within a string, it is not dangerous to
queries. Addslashes() forces the user input not to terminate a string, so as long as you enclose
the validated user input in a string, there's no danger with those particular two bits of
syntax.
On a completely different note, I think yet another good way to secure passwords, etc. from being
readable by someone with access to the server is to place them in functions in compiled files so
that they are not just plain text. This works with Java classes, and I imagine it works with COM
and .NET as well. My only problem with this is that the Java to PHP interaction and the .NET
functionality are not yet solidly defined, and COM doesn't work under anything but Windows.
I'd appreciate it if someone would post a way better than Java to do this on a non-Windows
system.