Being safe with user's input

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • moishy
    New Member
    • Oct 2006
    • 104

    #1

    Being safe with user's input

    All-in-all, what steps should be taken to insure a safe input.
    There are many precautions, can anybody fill me in on the rest.
    • Trim white spaces
    • Check for invalid characters
    • Make string to lowercase (in some cases)


    Is there anything that I missed?
  • realin
    Contributor
    • Feb 2007
    • 254

    #2
    Originally posted by moishy
    All-in-all, what steps should be taken to insure a safe input.
    There are many precautions, can anybody fill me in on the rest.
    • Trim white spaces
    • Check for invalid characters
    • Make string to lowercase (in some cases)


    Is there anything that I missed?

    hiya

    strip slashes
    strip tags
    and there is no way you can be 100% safe :P

    Comment

    • moishy
      New Member
      • Oct 2006
      • 104

      #3
      Can somebody please make a function that does it all.

      Comment

      • Atli
        Recognized Expert Expert
        • Nov 2006
        • 5062

        #4
        Hi.

        I usually just run the input through the htmlspecialchar s function. It converts all HTML tags into characters that the browser will display as text rather than parse into something nasty. Does nicely unless I am looking for something more specific, like SQL injection or something like that.

        This, as well as everything else, is never 100% safe, but it will neutralize most attempts to harm blogs and forums. People that do that kind of stuff are usually idiots trying to impress other idiots by showing of their non-existing hacking skills. I won't loose much sleep worrying about that.

        If you were to specify what kind of input you are talking about we might have some more specific answers.

        Comment

        • beepdev
          New Member
          • Nov 2007
          • 4

          #5
          Code:
          function secureData($string, $lowercase = false)
          {
          $string = trim($string);
          $sting = htmlspecialchars($string);
          
          if ($lowercase)
          $string = strtolower($string);
          
          $string = stripslashes($string);
          
          return $string;
          }
          call it like:
          Code:
          $sting = secureData($string, false);

          Comment

          • beepdev
            New Member
            • Nov 2007
            • 4

            #6
            Originally posted by beepdev
            Code:
            function secureData($string, $lowercase = false)
            {
            $string = trim($string);
            $sting = htmlspecialchars($string);
            
            if ($lowercase)
            $string = strtolower($string);
            
            $string = stripslashes($string);
            
            return $string;
            }
            call it like:
            Code:
            $sting = secureData($string, false);

            If only I could spell

            Code:
            function secureData($string, $lowercase = false)
            {
            $string = trim($string);
            $string = htmlspecialchars($string);
            
            if ($lowercase)
            $string = strtolower($string);
            
            $string = stripslashes($string);
            
            return $string;
            }
            call it like:
            Code:
            $string = secureData($string, false);

            Comment

            • moishy
              New Member
              • Oct 2006
              • 104

              #7
              I wanted to retrieve a simple alphanumeric string through URL.
              This is what I made, (and again, every case is different, and you'll never be %100 safe):
              [PHP]
              function clean($str){
              $str=strtolower ($str);
              $str=trim($str) ;
              $str=htmlspecia lchars($str);
              $str=preg_repla ce('/[^A-Za-z0-9 ]/', '', $str);
              $str=stripslash es($str);
              return $str;}[/PHP]
              Calling it:
              [PHP]$id = clean($_REQUEST['id']);[/PHP]
              What's your opinion? Fine?

              Comment

              Working...