On 2/15/07, Chris Shiflett <[EMAIL PROTECTED]> wrote:

http://nyphp.org/phundamentals/storingretrieving.php

Thanks for the link, Chris. I have been looking over your PHP security
book, the PHP Cookbook and Programming PHP tonight to try to refresh
myself on this topic. This article will help immensely.

As an aside, your filtering looks very lenient. What is the purpose of
that particular function?

That function basically is supposed to only allow the characters that
are included in the regex. The more and more I look at it, the more
and more I realize that it's just been bad from the start.

--
Randal Rust
R.Squared Communications
www.r2communications.com
_______________________________________________
New York PHP Community Talk Mailing List
http://lists.nyphp.org/mailman/listinfo/talk

NYPHPCon 2006 Presentations Online
http://www.nyphpcon.com

Show Your Participation in New York PHP
http://www.nyphp.org/show_participation.php

Reply via email to