I am looking at how to correctly avoid data coming from the outside world before it will be used for application management, storage, logic .. this kind of thing.
Obviously, with the quotes directive mask, deprecated in php 5.3.0+ and removed in php6, this becomes more urgent for those who want to upgrade and enter new language functions, while preserving the outdated code (don, t we like it ..).
However, one thing I have not seen is a lot of discussion about theory / best practice with what to do after protecting your data - for example, to store with or without a slash? I personally think that saving data to the database is not going well, but you want to hear a discussion and better read some examples.
Some links from the PHP manual are for reference only:
PHP Guide - mysql_real_escape_string
PHP Guide - htmlspecialchars
etc.
Any tips?
source
share