Php prevents SQL injection into code instances. Put it in a public call file (such as a conn Database link file) to filter all GET or POST data with special strings, to implement simple and effective SQL injection filtering, copy the code to the public call file (such as the conn Database link file) and filter special strings for all GET or POST data, to implement simple and effective SQL injection filtering
The code is as follows:
Function inject_check ($ SQL _str ){
Return eregi ('select | insert | and | or | update | delete | \ '| \/\ * | \. \. \/| \. \/| union | into | load_file | outfile ', $ SQL _str );
}
If (inject_check ($ _ SERVER ['query _ string']) = 1 or inject_check (file_get_contents ("php: // input") = 1 ){
// Echo "warns of illegal access! ";
Header ("Location: Error. php ");
}
Filters (such as the conn Database link file) to filter special strings for all GET or POST data to implement simple and effective SQL injection filtering code as follows...