Buy Sell Discuss UK Domain Names at AcornDomains.co.uk Free Virtual Servers

Today's Drop Dates are: 07-11-2011 or 14-11-2011   All times are GMT. The time now is 08:13:01 PM.
Domain Name Sales Domain Software Calculate UK Domain Drop Dates Domain Registration NameDrive Domain Parking Subscribe to our Domains For Sale newsletter
Go Back   Domain Forum Acorn Domains Buy Sell Auction UK Domains > Website Design and Promotion > Website Design > Scripts and Coding
Connect with Facebook

Scripts and Coding PHP, MySQL, scripts

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 03-02-2009, 03:35:55 AM     #11 (permalink)

 
woopwoop's Avatar
 
Join Date: Jan 2007
Posts: 1,483
woopwoop has a reputation beyond reputewoopwoop has a reputation beyond reputewoopwoop has a reputation beyond reputewoopwoop has a reputation beyond reputewoopwoop has a reputation beyond reputewoopwoop has a reputation beyond reputewoopwoop has a reputation beyond reputewoopwoop has a reputation beyond reputewoopwoop has a reputation beyond reputewoopwoop has a reputation beyond reputewoopwoop has a reputation beyond repute

Thanks skinner.

I've been working with addslashes instead of preg_replace() to put a string as a page title.

Quote:
<title><?php $pagetitle = mysql_real_escape_string($pagetitle); echo $pagetitle;?></title>
This outputs the Japanese without any issue now that my earlier encoding problem is fixed. I wondered if addslashes is enough in this case?

I think that the worst that can happen is that the title may appear as
Quote:
title text \"some word with a\" quote
if there are single or double quotes used (which I can live with)

I tried htmlentities and mysql_real_escape_string but both gave errors in the title when using Japanese. But addslashes seemed fine - as long as it's safe.

These are all functions that I've used a few times in websites but I'd never really carried out a full security check.
woopwoop is offline  
Old 03-02-2009, 03:59:22 AM     #12 (permalink)

 
Skinner's Avatar
 
Join Date: Jul 2008
Location: Manchester
Posts: 2,501
Skinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond repute

Add Slashes will stop most Injection Methods, real escape is just a more SQL geared method.

Even if you ran all 3 and a replacement, you can't say its safe as someone will find a way if they really want to, so just take basic steps

I personally use htmlentities only where allowing html input by anyone other than me, I use real escape or add slashes for none-html code.
__________________
Browse:
Skinner is offline  
Closed Thread



Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Domain Name Community Replies Last Post
A question from buy.at Tyson Pearcey Affiliate Marketing 21 05-02-2008 03:26:35 PM
123-Reg noddy question bb99 Domain Name Registrars 3 20-02-2007 01:59:18 PM
Google Network & Parking Programs Question? sneezycheese Internet Marketing 0 08-10-2006 10:35:58 AM
Question about DRS etc Brassneck Domain Name Disputes 2 10-10-2005 05:13:34 PM

Reseller Hosting


All times are GMT. The time now is 08:13:01 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.6.0 RC 2
All content on Acorn Domains is member generated and is not moderated before posting. All content is viewed and used by you at your own risk and AD does not warrant the accuracy or reliability of any of the information. The views expressed are those of the individual contributors and not necessarily those of AD. Please contact us to report any issues or send a PM to "Admin".