You are here: Re: The best way to protect SQL injection? « PHP Programming Language « IT news, forums, messages
Re: The best way to protect SQL injection?

Posted by Dikkie Dik on 12/27/06 16:43

> The suggested way to protect user-supplied input to with MySQL involves
> using a special PHP function for MySQL:
>
> mysql_real_escape_string (PHP 4 >= 4.3.0, PHP 5)
>
> http://www.php.net/manual/en/function.mysql-real-escape-string.php
>
> This takes the character set used by the database into account.


I know. And that is a severe problem for me. At the time I build the
queries, there may not even be a database connection. I do not want it
to work with a current database connection, I want it to work with _all_
database connections. SQL itself is just normal 7-bits ASCII (there may
be ways to configure the server otherwise, but I don't do that) and it
is only the strings that have to be escaped. So what is safer than
building the entire command in 7-bits ASCII?

Best regards

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация