![]() |
|
| Domain Name Sales | Domain Software | Calculate UK Domain Drop Dates | Domain Registration | NameDrive | Domain Parking | Subscribe to our Domains For Sale newsletter |
| | ||||||
| Home | Register | Rules | Membership Upgrade | Domains For Sale | Domain Name Escrow | Mark Forums Read | Domain Classified | Chat Room |
| Scripts and Coding PHP, MySQL, scripts |
![]() |
| | LinkBack | Thread Tools | Display Modes |
| | #11 (permalink) | ||
![]() |
Thanks skinner. I've been working with addslashes instead of preg_replace() to put a string as a page title. Quote:
I think that the worst that can happen is that the title may appear as Quote:
I tried htmlentities and mysql_real_escape_string but both gave errors in the title when using Japanese. But addslashes seemed fine - as long as it's safe. These are all functions that I've used a few times in websites but I'd never really carried out a full security check.
__________________ Connect with me @ TW:LI:FB | MyWeb | D/L domains4sale | Morecambe London Student Forums Student Books UK promotions agencies | ||
| |
| | #12 (permalink) |
![]() |
Add Slashes will stop most Injection Methods, real escape is just a more SQL geared method. Even if you ran all 3 and a replacement, you can't say its safe as someone will find a way if they really want to, so just take basic steps I personally use htmlentities only where allowing html input by anyone other than me, I use real escape or add slashes for none-html code.
__________________ Browse: |
| |
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Domain Name Community | Replies | Last Post |
| A question from buy.at | Tyson Pearcey | Affiliate Marketing | 21 | 05-02-2008 03:26:35 PM |
| 123-Reg noddy question | bb99 | Domain Name Registrars | 3 | 20-02-2007 01:59:18 PM |
| Google Network & Parking Programs Question? | sneezycheese | Internet Marketing | 0 | 08-10-2006 10:35:58 AM |
| Question about DRS etc | Brassneck | Domain Name Disputes | 2 | 10-10-2005 05:13:34 PM |