To continue the discussion on PHP application security, pay attention to the following aspects:
1. Filter SQL injection attacks
You can use PHP built-in functions such as addslashes to directly provide functions for ease of use.
Function verifyinput ($ input)
{
If (! Get_magic_quotes_gpc ())
{
// Magic_quotes_gpc is on by default and will automatically escape characters such '.
$ Input = addslashes ($ input );
}
}
In the display mode
<? Echo htmlentities (stripslashes (...)?> Normal display
You can simply use the mysql_real_escape_string function to filter data.
2. determine the type of the variable. For example, determine whether the input variable is an integer.
If (is_numeric ($ PID )).........
But we need to limit the length. It is best to write a function to determine whether it is a pure number, for example
If (strlen ($ PID )){
If (! Ereg ("^ [0-9] + $", $ PID) & strlen ($ PID)> 5 ){
An example is provided.
....................
/**
* Checks whether $ Val is a pure number.
* @ Param $ Val value entered by the user
* @ Param $ stuff: $ Val is required when it is set to true. If it is set to false, $ Val is not required.
* @ Param $ when mixlen is a numeric value, it indicates that the value of $ Val must reach the length of $ mixlen. If you do not need to check, enter-1.
* @ Param $ when maxlen is a numerical value, it indicates that the value of $ Val must be less than the length of $ maxlen. If you do not need to check a large value of interval, you can
* @ Return $ Val returns true if the format is valid; otherwise, false.
*/
Function checknumberonly ($ Val, $ stuff, $ mixlen, $ maxlen)
{
If ($ stuff = true)
{
If ($ val = "")
Return false;
If (strlen ($ Val) <$ mixlen | strlen ($ Val)> $ maxlen)
Return false;
If (! Eregi ("^ [0-9] + $", $ Val ))
Return false;
}
Else if ($ stuff = false)
{
If ($ Val! = "")
{
If (strlen ($ Val) <$ mixlen | strlen ($ Val)> $ maxlen)
Return false;
If (! Eregi ("^ [0-9] + $", $ Val ))
Return false;
}
}
Return true;
}
3. Clear the HTML Tag entered by the user. If it is determined that the user does not need to enter the HTML Tag, filter it out. For example:
$ Name = strip_tags ($ _ post ['name']);
Use strip_tags to clear HTML tags
Then determine whether the rule is true for letters and numbers.
$ Name = cleanhex ($ name );
Function cleanhex ($ input ){
$ Clean = preg_replace \
("! [\] [XX] ([A-Fa-f0-9 })! "," ", $ Input );
Return $ clean;
}
To completely restore the HTML Tag entered by the user, use htmlspecialchars ().
4. Prevent remote form submission
To prevent users from retaining the form page and modifying and submitting it, you can use the token verification method, as shown in
<? PHP
Session_start ();
If ($ _ post ['submit '] = "go "){
If ($ _ post ['Token'] = $ _ session ['Token']) {
$ Name = strip_tags ($ _ post ['name']);
} Else {
}
}
$ Token = MD5 (uniqid (RAND (), true ));
$ _ Session ['Token'] = $ token;
?>
<Form action = "<? PHP echo $ _ server ['php _ Self '];?> "Method =" Post ">
<P> <label for = "name"> name </label>
<Input type = "text" name = "name" id = "name" size = "20" maxlength = "40"/> </P>
<Input type = "hidden" name = "token" value = "<? PHP echo $ token;?> "/>
<P> <input type = "Submit" name = "Submit" value = "go"/> </P>
</Form>