note 38224 deleted from security.variables by aidan

From: Date: Tue, 07 Sep 2004 23:32:10 +0000
Subject: note 38224 deleted from security.variables by aidan
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-76178@lists.php.net to get a copy of this message
Note Submitter: editor at phpconsulting dot com ---- The following code snippit was written by Mat Caughron, CISSP, in preparation for a final examination in a course he taught called "Real World PHP" at the University of Nebraska Omaha. <?php foreach ($_POST as $postvarname => $rawpostcontent) { array_push($_POST[$postvarname], strip_tags(substr(trim($rawpostcontent),0,250))); } ?> It provides a simple way to apply safe data handling functions (such as strip_tags and string truncation with substr) to all incoming $_POST variables and addresses three of the OWASP top ten web programming mistakes mentioned at: http://www.sklar.com/page/article/owasp-top-ten Note that, as written, it will truncate all incoming variables to 250 characters.

« previous php.notes (#76178) next »