Reply to Re: Strategy for securing MySQL PHP application - please comment

Your name:

Reply:


Posted by Harold Crump on 07/05/06 03:19

> > What's the issue with storing the &quote in the database?
>
> What if you want to use the data for other than displaying on the web? For instance, another
> (non-web) application is going to print information from the database? It might even be a C/C++
> application, for instance.

Point taken.
This application, however, is web-only.
I don't anticipate any non-web consumer for this data.
If that does indeed come to pass, I figure it will be easy enough to
write a script that HTML decodes everything and saves it back into the
database with escaped characters - no?

> > Why bother with mysql_real_escape_string and all its inherent issues if
> > we can completely eliminate quotes from making their way into the SQL
> > statement?
> >
>
> Because mysql_real_escape takes the current charset into account when performing its operations.

So does htmlentities()

> > What am I missing?
> >
>
> The fact that not everything in the world is html based?

No?
You mean you don't dream in HTML?
Where're you from? :p

-Harold.

[Back to original message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация