You are here: Re: database injection « All PHP « IT news, forums, messages
Re: database injection

Posted by Peter van Schie on 07/14/06 19:27

Mike schreef:
> I have read through lots of messages about database injection but I'm
> still a bit confused.
>
> I have a website where users input data either for searching or storing
> on a database such as logging in or storing personal data in the
> database.
>
> I'm confused what commands to use to make sure commands such as DROP
> etc are not entered.
>
> I've seen stripslashes(), addslashes(), striptags() etc. What should
> be used?

Take a look at mysql_real_escape_string. It's also a good idea to setup
a mysql useraccount for all queries from the users. Simply don't allow
that account to execute DROP queries and only allow it to execute
queries you really need.

HTH.
Peter.
--
http://www.phpforums.nl

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация