


Simple analysis of preventing sql injection in php, phpsql injection_PHP tutorial
Jul 13, 2016 am 10:02 AMA simple analysis of php to prevent sql injection, phpsql injection
This article analyzes a simple method of php to prevent sql injection. Share it with everyone for your reference. The details are as follows:
Here is just a simple method
There are many ways to prevent Sql injection. What I want to talk about here is actually one of the methods in the vulnerability drill platform Dvwa
Just look at the high level ones
$id = $_GET['id']; $id = stripslashes($id); $id = mysql_real_escape_string($id); if (is_numeric($id)){ $getid = "SELECT first_name,last_name FROM users WHERE user_id='$id'"; $result = mysql_query($getid) or die('<pre>'.mysql_error().'</pre>'); $num = mysql_numrows($result);
It can be seen that the way it is processed is to first remove the backslashes in the variable through the stripslashes function,
Then use the function mysql_real_escape_string to escape special characters.
So when we write code like
$getid="SELECT first_name,last_name FROM users WHERE user_id='$id'";
Our simplest method is
Directly process the variable $id with stripslashes and mysql_real_escape_string.
Note: This is not to say that this is safe. This is just one of the methods. I am not saying that this is safe. More needs to be dealt with based on the actual situation.
I hope this article will be helpful to everyone’s PHP programming design.

Hot Article

Hot tools Tags

Hot Article

Hot Article Tags

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics

PHP 8.4 Installation and Upgrade guide for Ubuntu and Debian

How To Set Up Visual Studio Code (VS Code) for PHP Development
