Very useful php prevents SQL injection vulnerability filtering function code
- // PHP full-site anti-injection program, which must be included in the public file require_once
- // Determine the magic_quotes_gpc status
- If (@ get_magic_quotes_gpc ()){
- $ _ GET = sec ($ _ GET );
- $ _ POST = sec ($ _ POST );
- $ _ COOKIE = sec ($ _ COOKIE );
- $ _ FILES = sec ($ _ FILES );
- }
- $ _ SERVER = sec ($ _ SERVER );
- Function sec (& $ array ){
- // If it is an array, traverse the array and call it recursively
- If (is_array ($ array )){
- Foreach ($ array as $ k => $ v ){
- $ Array [$ k] = sec ($ v );
- }
- } Else if (is_string ($ array )){
- // Use the addslashes function for processing
- $ Array = addslashes ($ array );
- } Else if (is_numeric ($ array )){
- $ Array = intval ($ array );
- }
- Return $ array;
- }
- // Integer filter function
- Function num_check ($ id ){
- If (! $ Id ){
- Die ('parameter cannot be blank! ');
- } // Whether it is null
- Else if (inject_check ($ id )){
- Die ('invalid parameter ');
- } // Injection judgment
- Else if (! Is_numetic ($ id )){
- Die ('invalid parameter ');
- }
- // Digital judgment
- $ Id = intval ($ id );
- // Integer
- Return $ id;
- }
- // Character filtering function
- Function str_check ($ str ){
- If (inject_check ($ str )){
- Die ('invalid parameter ');
- }
- // Injection judgment
- $ Str = htmlspecialchars ($ str );
- // Convert html
- Return $ str;
- }
- Function search_check ($ str ){
- $ Str = str_replace ("_", "\ _", $ str );
- // Filter out "_"
- $ Str = str_replace ("%", "\ %", $ str );
- // Filter out "%"
- $ Str = htmlspecialchars ($ str );
- // Convert html
- Return $ str;
- }
- // Form filter function
- Function post_check ($ str, $ min, $ max ){
- If (isset ($ min) & strlen ($ str) <$ min ){
- Die ('minimum $ min Byte ');
- } Else if (isset ($ max) & strlen ($ str)> $ max ){
- Die ('maximum $ max Byte ');
- }
- Return stripslashes_array ($ str );
- }
- // Anti-injection function
- Function inject_check ($ SQL _str ){
- Return eregi ('select | inert | update | delete | \ '| \/\ * | \. \. \/| \. \/| UNION | into | load_file | outfile ', $ SQL _str );
- // Filter and prevent injection
- }
- Function stripslashes_array (& $ array ){
- If (is_array ($ array )){
- Foreach ($ array as $ k => $ v ){
- $ Array [$ k] = stripslashes_array ($ v );
- }
- } Else if (is_string ($ array )){
- $ Array = stripslashes ($ array );
- }
- Return $ array;
- }
- ?>
|