Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 185
  • Last Modified:

escaping input into db

Is the following function good enough to make sure my php app doesn't get hacked?
also will this allow html to be displayed corretly?
its for CMS so its has to deal with just about any kind of input.
function db_escape($values, $quotes = true) {
    if (is_array($values)) {
        foreach ($values as $key => $value) {
            $values[$key] = db_escape($value, $quotes);
        }
    }
    else if ($values === null) {
        $values = 'NULL';
    }
    else if (is_bool($values)) {
        $values = $values ? 1 : 0;
    }
    else if (!is_numeric($values)) {
        $values = mysql_real_escape_string($values);
        if ($quotes) {
            $values = '"' . $values . '"';
        }
    }
    return $values;
}

Open in new window

0
casit
Asked:
casit
  • 2
  • 2
1 Solution
 
XemorphCommented:
It looks fine to me.  I think it will prevent any SQL injection attacks, I don't know about making your app hack proof.

I would add cases for int or float and use intval() and floatval().  Just to cover all cases.
0
 
casitAuthor Commented:
and do what with them?
0
 
XemorphCommented:

function db_escape($values, $quotes = true) {
    if (is_array($values)) {
        foreach ($values as $key => $value) {
            $values[$key] = db_escape($value, $quotes);
        }
    }
    else if ($values === null) {
        $values = 'NULL';
    }
    else if (is_bool($values)) {
        $values = $values ? 1 : 0;
    }
    else if (!is_numeric($values)) {
        $values = mysql_real_escape_string($values);
        if ($quotes) {
            $values = '"' . $values . '"';
        }
    }
 
    // ADD THIS
    else if(is_float($values){
        $values = floatval($values);
    }
    else
        $values = intval($values);
    }
 
    // End with an else so we have a case for all possiable inputs.
    // If you find another possiable input, add it to the else if list.
    // I would always end on an else though, incase you did 
    // miss something
 
    return $values;
}

Open in new window

0
 
casitAuthor Commented:
thanks
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now