May 31, 201313 yr Hello, So I have two questions 1. What is a safe way to retrieve data from a database and then later for output. So I insert some data in a form and place that in the database, what is then the safest way? By insert using htmlentities or by outputing? 2. So I have an item with an itemnumber in the url like this: localhost/Project/items.php?itemnumber=12 How can I secure this with PHP, so when you would typ in a quote for example, that the data is sanitized, so I can prevent SQL injection! localhost/Project/items.php?itemnumber='DROP DATABASE'; Cheers
May 31, 201313 yr I think your best bet is to use PDO or Mysqli with prepared statements and parameterized queries. (LINK) These take care of quote handling for you. Obviously, there will be other methods for injection, some further info: http://stackoverflow.com/questions/134099/are-pdo-prepared-statements-sufficient-to-prevent-sql-injection
Create an account or sign in to comment