Solved

Regular expression to checking ...?

Posted on 2008-06-24
4
210 Views
Last Modified: 2008-06-25
Hello group,

How can I avoid users from entering some specific characters in Form entries? characters such as & ^ % # @ and so on?

I don't know that much about Regular Expression but will appreciate it if you pass me some links to learn how to use it in PHP.

Regards.
0
Comment
Question by:akohan
  • 2
  • 2
4 Comments
 
LVL 2

Accepted Solution

by:
CurtinProp earned 150 total points
ID: 21862462



$banned = array("#","^","%");

$text = "This is 20% of the total #number of ^carrots";

$string = str_replace($banned, "", $text);
 

If you echo string it would display;

This is 20 of the total number of carrots
 

Now this is a simple approach, regular expressions would be the best sollution if it got more advanced. If your trying make your forms safe from XSS attacks or SQL injection i'd suggest using alternate frameworks to assist you.

Open in new window

0
 

Author Comment

by:akohan
ID: 21863119

Hi CurtinProp,

You did point to something I always think of. As matter of fact, I've started PHP just few months ago and not sure what XSS attaks are. Would you please give me direction toward this concept? Any online resource or book would be great.


Thanks.
0
 
LVL 2

Expert Comment

by:CurtinProp
ID: 21863158
Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications which allow code injection by malicious web users into the web pages viewed by other users. Examples of such code include HTML code and client-side scripts.
http://en.wikipedia.org/wiki/Cross-site_scripting

For books I suggest;
http://www.amazon.com/Cross-Site-Scripting-Attacks-Exploits/dp/1597491543/ref=pd_bbs_sr_1/104-1412087-4929535?ie=UTF8&s=books&qid=1177355137&sr=1-1

This book was written by industry experts and is the best reference.

He also has a blog which I also read; www.jeremiahgrossman.blogspot.com/
0
 

Author Comment

by:akohan
ID: 21863546

Wow! thank you so much for the details.

Regards.
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Introduction Many web sites contain image galleries; a common design for these galleries includes a page with a collection of thumbnail images.  You can click on each of the thumbnail images to see the larger version of the image.  This is easily i…
Generating table dynamically is the most common issue faced by php developers.... So it seems there is a need of an article that explains the basic concept of generating tables dynamically. It just requires a basic knowledge of html and little maths…
Learn how to match and substitute tagged data using PHP regular expressions. Demonstrated on Windows 7, but also applies to other operating systems. Demonstrated technique applies to PHP (all versions) and Firefox, but very similar techniques will w…
The viewer will learn how to look for a specific file type in a local or remote server directory using PHP.

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now