Input value/form submission parameter filtering to prevent SQL injection or illegal attacks:
Copy codeThe Code is as follows:
/**
* Filter keywords for SQL and PHP File Operations
* @ Param string $ string
* @ Return string
* @ Author zyb <zyb_icanplay@163.com>
*/
Private function filter_keyword ($ string ){
$ Keyword = 'select | insert | update | delete | \ '| \/\ * | \. \. \/| \. \/| union | into | load_file | outfile ';
$ Arr = explode ('|', $ keyword );
$ Result = str_ireplace ($ arr, '', $ string );
Return $ result;
}
/**
* Check whether the entered number is valid. The corresponding id is valid; otherwise, false is returned.
* @ Param integer $ id
* @ Return mixed
* @ Author zyb <zyb_icanplay@163.com>
*/
Protected function check_id ($ id ){
$ Result = false;
If ($ id! = ''&&! Is_null ($ id )){
$ Var = $ this-> filter_keyword ($ id); // filter keywords for SQL and PHP File Operations
If ($ var! = ''&&! Is_null ($ var) & is_numeric ($ var )){
$ Result = intval ($ var );
}
}
Return $ result;
}
/**
* Check whether the entered characters are valid. The corresponding id is valid; otherwise, false is returned.
* @ Param string $ string
* @ Return mixed
* @ Author zyb <zyb_icanplay@163.com>
*/
Protected function check_str ($ string ){
$ Result = false;
$ Var = $ this-> filter_keyword ($ string); // filter keywords for SQL and PHP File Operations
If (! Empty ($ var )){
If (! Get_magic_quotes_gpc () {// determines whether magic_quotes_gpc is enabled.
$ Var = addslashes ($ string); // filter submitted data when magic_quotes_gpc is not enabled
}
// $ Var = str_replace ("_", "\ _", $ var); // filter '_'
$ Var = str_replace ("%", "\ %", $ var); // filter '%'
$ Var = nl2br ($ var); // press enter to convert
$ Var = htmlspecialchars ($ var); // html tag Conversion
$ Result = $ var;
}
Return $ result;
}