Re: how to sanitize user inpuit using HTML_QuickForm?
| From: | Justin Patrin | Date: | Thu, 11 Nov 2004 18:32:32 +0000 |
| Subject: | Re: how to sanitize user inpuit using HTML_QuickForm? | ||
| References: | 1 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-15454@lists.php.net to get a copy of this message | ||
On Thu, 11 Nov 2004 05:52:33 -0800 (PST), Stowe Spivey
<spiveyspivey@yahoo.com> wrote:
> I am thinking about using regex to weeb out any troubling characters
> that could be used to do hack the system, cross-site exploits or SQL
> injection.
>
> Would the alphnumeric filter do the same thing?
>
> Any other ideas or your experiences would be greatly appreciated!
>
> As an aside, let me congratulate the people who came up with this
> package - I think it's phenomenal!
>
You can use regexes and such, but IMHO it's much better practice to
"escape" things in the right places. When inserting into the DB, use
quoting functions (mysql_real_escape_string() or
PEAR::DB->quoteSmart()) and when outputting to HTML, use
htmlentities().
For more: http://www.reversefold.com/tikiwiki/tiki-index.php?page=PHPFAQs#id15878
--
Justin Patrin