MySQL and PHP Security

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • wwolfson
    New Member
    • Jun 2007
    • 13

    MySQL and PHP Security

    Hiya all,
    I am currently building a forum for a website I have made. However, one thing is bothering me. It seems that (although I dare try) if you input sql into the form fields, it would be possible to delete all my tables and run sql commands.
    What can I do to prevent this??
    On my registration page, all the fields have validation such that it is impossible to enter an SQL query but on a forum when the possible response can be anything I do not know what to do.
    Thanks,
    William
  • mwasif
    Recognized Expert Contributor
    • Jul 2006
    • 802

    #2
    Use htmlentities() with ENT_QUOTES quotes style and required charset. The charset can be UTF-8.

    Comment

    • wwolfson
      New Member
      • Jun 2007
      • 13

      #3
      thanks i will give it a try.

      Comment

      • mwasif
        Recognized Expert Contributor
        • Jul 2006
        • 802

        #4
        Also consider the use of htmlspecialchar s().

        Comment

        Working...