Re: how to sanitize user inpuit using HTML_QuickForm?

From: Date: Thu, 11 Nov 2004 18:32:32 +0000
Subject: Re: how to sanitize user inpuit using HTML_QuickForm?
References: 1  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-15454@lists.php.net to get a copy of this message
On Thu, 11 Nov 2004 05:52:33 -0800 (PST), Stowe Spivey <spiveyspivey@yahoo.com> wrote: > I am thinking about using regex to weeb out any troubling characters > that could be used to do hack the system, cross-site exploits or SQL > injection. > > Would the alphnumeric filter do the same thing? > > Any other ideas or your experiences would be greatly appreciated! > > As an aside, let me congratulate the people who came up with this > package - I think it's phenomenal! > You can use regexes and such, but IMHO it's much better practice to "escape" things in the right places. When inserting into the DB, use quoting functions (mysql_real_escape_string() or PEAR::DB->quoteSmart()) and when outputting to HTML, use htmlentities(). For more: http://www.reversefold.com/tikiwiki/tiki-index.php?page=PHPFAQs#id15878 -- Justin Patrin

« previous php.pear.general (#15454) next »