note 37155 deleted from security.globals by philip
| From: | philip@php.net | Date: | Wed, 14 Jul 2004 21:44:04 +0000 |
| Subject: | note 37155 deleted from security.globals by philip | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-73241@lists.php.net to get a copy of this message | ||
Note Submitter: cameronNO_SPAM@tripdubdev.com
----
Here's a useful bit of code I created (can be used for ANY of the different types of variables
GET, POST, COOKIES, etc...)
It's basically a filter that will allow you to pre-filter ALL variables before using them in
your code, reducing risks of security holes at the application level.
Any feedback is greatly appreciated.
<?
$alphabet="\r\n abcdefghijklmnopqrstuvwxyz1234567890<>=/._";
$post=$_POST;
$get=$_GET;
$postcount=count($post) -1;
$getcount=count($get) -1;
$getkeys=array_keys($get);
$postkeys=array_keys($post);
while($getcount>0) {
$key=$getkeys[$getcount];
$variable=$get[$key];
$variable=$variable1=trim(strtolower($variable));
$vnum=0;
while($variable2=$variable1[$vnum]) {
if(!strstr($alphabet,$variable2) || $variable2=="\"") {
$variable=str_replace($variable2,'',$variable);
}
$vnum=$vnum+1;
}
$_GET[$key]=$variable;
$getcount=$getcount-1;
}
while($postcount>0) {
$key=$postkeys[$postcount];
$variable=$post[$key];
$variable=$variable1=trim(strtolower($variable));
$vnum=0;
while($variable2=$variable1[$vnum]) {
if(!strstr($alphabet,$variable2) || $variable2=="\"") {
$variable=str_replace("$variable2","",$variable);
}
$vnum=$vnum+1;
}
$_POST[$key]=$variable;
$postcount=$postcount-1;
}
?>