Skip to content
TORNLIFE More

Security Function for users, that are using SQL

Started by AAW [1525734] on in API Development.

3 replies · 62 views · thread synced · 4 days ago · View on torn.com
About this thread

Posts archived: 4 / 4 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
4
Discussion span
→
People posting
3
Likes on archived posts
3
Authority score
50 / 100
Historical score
16 / 100
Story score
25 / 100
Engagement score
42 / 100
AAW [1525734]

Here is a security function that will stop SQL Injection from being made, if your using MYSQL too store Usernames, Passwords, API Keys and data like this!


function protect($variable)
{$var = strip_tags(mysql_real_escape_string(trim($variable)));
$strip = strip_tags($variable);
$sql = mysql_real_escape_string($strip);
$variable = trim($sql);
return $variable;
}
Plornt [1799359]

Jesus christ, get rid of that incredibly outdated shit, use mysql prepared statements and use htmlspecialchars when outputting to the page if you're not using a framework that does that for you. I am assuming you noticed "someone" was able to make it output javascript to the admin account of your website ^^