TalkPHP
 
 
Account Login
Latest Articles
» The basic usage of PHPTAL, a XML/XHTML template library for PHP
» Vulnerable methods and the areas they are commonly trusted in.
» Simple way to protect a form from bot
» The Basics On: How Session Stealing Works
» How to keep your forms from double posting data
IRC Channel
IRC Speech Bubble Join the friendly bunch on IRC...
(#TalkPHP on Freenode)

...Also available via a web interface.

See this thread for information on the TalkPHP Free Hugs Initiative™. Subject to availability.
Associates
Associates
CSS Tutorials
Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 12-10-2008, 03:57 AM   #1 (permalink)
The Contributor
 
Join Date: Feb 2007
Posts: 64
Thanks: 9
Killswitch is on a distinguished road
Default sttripslashes, addslashes, magic quotes, queries...

I have been doing some reading and I get different answers from different sources. My question comes into play regarding the integrity of securing database queries.

For the longest time, I have simply been checking my magic quotes settings and addslashes if it was off. Today I was reading an article and I believe I should ALSO be stripping the slashes if magic quotes is on when using mysql_real_escape_string. Is this true and if so, what does this do? Double escaping??

I've also come to find that neither protects you from attacks using LIKE and similar. I had a hard time finding an answer to preventing these attacks, some relied on str_replace and other methods but .. should I be using addcslashes instead of using addslashes to excape this data? I've been reading up at the manual for awhile researching this problem and it seems like a good solution, though I have never used it to see any results. Would this be safe?
Killswitch is offline  
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Differences Between Single and Double Quotes Wildhoney General 19 11-10-2007 11:37 PM


All times are GMT. The time now is 08:06 AM.

 
     

Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Inactive Reminders By Icora Web Design