Filtering & Escaping
Use r In put
Validation
ctype_alpha() ctype_digit() ctype_alnum() ctype_lower() ctype_upper() preg_match()
a ma e s, i t's (y
nt ra)
Tainted Data
Alphabetical Numerical Alphanumeric Lowercase Uppercase E-Mail Addresses Phone Numbers Credit Cards Zip Codes HTML Control Characters Slashes
strip_tags() preg_replace() str_replace() stripslashes() urldecode() rawurlencode()
Filtering
l App
Yes, Databases are output too!
ic
n atio
u utp O
t
Validated & Filtered Data
Database
mysql_real_escape_string() pg_escape_string() sqlite_escape_string() maxdb::real_escape_stri
↧