note 38224 deleted from security.variables by aidan
| From: | aidan@php.net | Date: | Tue, 07 Sep 2004 23:32:10 +0000 |
| Subject: | note 38224 deleted from security.variables by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-76178@lists.php.net to get a copy of this message | ||
Note Submitter: editor at phpconsulting dot com
----
The following code snippit was written by Mat Caughron, CISSP, in preparation for a final
examination in a course he taught called "Real World PHP" at the University of Nebraska
Omaha.
<?php
foreach ($_POST as $postvarname => $rawpostcontent)
{
array_push($_POST[$postvarname],
strip_tags(substr(trim($rawpostcontent),0,250)));
}
?>
It provides a simple way to apply safe data handling functions (such as strip_tags and string
truncation with substr) to all incoming $_POST variables and addresses three of the OWASP top ten
web programming mistakes mentioned at: http://www.sklar.com/page/article/owasp-top-ten
Note that, as written, it will truncate all incoming variables to 250 characters.