note 44748 deleted from security by aidan
| From: | aidan@php.net | Date: | Tue, 07 Sep 2004 23:32:45 +0000 |
| Subject: | note 44748 deleted from security by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-76181@lists.php.net to get a copy of this message | ||
Note Submitter: duerra at notthis dot pushitlive dot net
----
Not enough can be said about checking data that the user has submitted. Most new PHP programmers I
come across suffer miserably from not doing any data validation.
Almost all data should go through something like this:
<?php
//Alright, these are the variables we're expecting from the user.
//This way we don't have to check for them later on.
$initArr = array('var1', 'var2', 'var3', 'var4');
foreach($initArr AS $var)
{
if(!isset($_POST[$var]))
{//If it's not set, set it
$_POST[$var] = FALSE;
}
else
{//Clean the variables we're expecting
$_POST[$var] = cleanVar($_POST[$var]);
}
}
//A general cleaning function. There may be times when you
//don't want to use this, but not very often....
function cleanVar($var)
{
//If the variable is an array, we want to clean those values, too
if(!is_array($var))
{
$var = array($var);
}
foreach($var AS $key => $value)
{
$value = go_add_slashes($value);
//Remove any HTML characters and replace them with the HTML entities
$value= htmlspecialchars($value);
//Remove any excess spacing in the beginning or end of the string
$value = trim($value);
$var[$key] = $value;
}
return $var;
}
//Magic quotes is enabled by default
//But in the event that our scripts are on a server
//that doesn't have them enabled, we'd be in big trouble
//So we check for it
//Without magic quotes, we are more vulnerable to SQL injection
function go_add_slashes($var)
{
if(!is_array($var))
{
$var = array($var);
}
if(!get_magic_quotes_gpc())
{
foreach($var AS $key => $value)
{
//Add slashes if magic quotes gpc is turned off to prevent SQL injection
$var[$key] = addslashes($value);
}
}
return $var;
}
?>