Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 1 of 2 12 LastLast
Results 1 to 10 of 15
  1. #1
    Join Date
    Sep 2006
    Location
    Evanston, Illinois.
    Posts
    2,361
    Tokens
    0

    Latest Awards:

    Default SQL Injection Protection

    Can somebody share there clean classes with me. I have quite a few things i need validating, and right now it's just at mysql_real_escape_string, it needs to process html though. Thats the only drawback, thanks!
    How could this hapen to meeeeeeeeeeeeeee?lol.

  2. #2
    Join Date
    Oct 2006
    Location
    Peterborough, UK
    Posts
    3,855
    Tokens
    216

    Latest Awards:

    Default

    uhh, forget that apparently this wysiwyg editor is absolutely stupid, just use this:

    http://pastebin.com/m2d7e3fd9
    Last edited by Jewish Bear; 09-03-2008 at 11:45 PM.


    visit my internet web site on the internet
    http://dong.engineer/
    it is just videos by bill wurtz videos you have been warned

  3. #3
    Join Date
    Sep 2006
    Location
    Evanston, Illinois.
    Posts
    2,361
    Tokens
    0

    Latest Awards:

    Default

    ty much
    How could this hapen to meeeeeeeeeeeeeee?lol.

  4. #4
    Join Date
    Jan 2007
    Location
    Canada eh?
    Posts
    766
    Tokens
    75

    Default

    The link Dan posted will work just fine but could you not/wouldn't it be wise to use that in conjunction with some other string replace queries (eg. SELECT FROM, UPDATE, DELETE, etc.)?

  5. #5
    Join Date
    Oct 2006
    Location
    Peterborough, UK
    Posts
    3,855
    Tokens
    216

    Latest Awards:

    Default

    Quote Originally Posted by Scriptz View Post
    The link Dan posted will work just fine but could you not/wouldn't it be wise to use that in conjunction with some other string replace queries (eg. SELECT FROM, UPDATE, DELETE, etc.)?
    Not really, with ''s out of the question any well formed SQL query wont have problems like that, I stopped removing stuff like that ages ago.


    visit my internet web site on the internet
    http://dong.engineer/
    it is just videos by bill wurtz videos you have been warned

  6. #6
    Join Date
    Mar 2008
    Location
    Here.
    Posts
    182
    Tokens
    0

    Default

    Test the divs.

  7. #7
    Join Date
    Sep 2006
    Location
    Evanston, Illinois.
    Posts
    2,361
    Tokens
    0

    Latest Awards:

    Default

    Who the heck are you? Oh Ivake, ok.
    How could this hapen to meeeeeeeeeeeeeee?lol.

  8. #8
    Join Date
    Mar 2008
    Posts
    173
    Tokens
    0

    Default

    Quote Originally Posted by Insedated View Post
    Test the divs.
    I have to agree, that was funny.

    Just addslashes?

  9. #9
    Join Date
    Sep 2006
    Location
    Evanston, Illinois.
    Posts
    2,361
    Tokens
    0

    Latest Awards:

    Default

    what about mysql_real_escape_string and htmlentities and all that jazz.
    How could this hapen to meeeeeeeeeeeeeee?lol.

  10. #10
    Join Date
    Mar 2008
    Posts
    173
    Tokens
    0

    Default

    You can use mysql_real_escape_string, but I advise against it.

    htmlentities has nothing to do with HTML injection.. that changes ^&$&U^& and all those symbols to their HTML version.

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •