note 50513 added to security.database.sql-injection
| From: | programmer at umistudio dot com | Date: | Wed, 02 Mar 2005 13:10:48 +0000 |
| Subject: | note 50513 added to security.database.sql-injection | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-85776@lists.php.net to get a copy of this message | ||
I think, this small script can be usefull against sql-injections.
<?
function ekran($var) {
if(is_array($var) != 1) {
if($var != mysql_real_escape_string($var))
error_inform();
return mysql_real_escape_string($var);
}
else
return array_filter($var);
}
function check_params() {
array_filter($_GET, "ekran");
array_filter($_POST, "ekran");
array_filter($_COOKIE, "ekran");
}
@import_request_variables("CGP", "");
?>
you can define "error_inform()" function to log(or send mail) abnormal values.
----
Manual Page -- http://www.php.net/manual/en/security.database.sql-injection.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+50513
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+50513&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+50513&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+50513&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+50513&report=yes&reason=useless
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+50513&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+50513&report=yes
Search -- http://master.php.net/manage/user-notes.php