Useful php code for preventing SQL injection vulnerability filtering functions-php Tutorial

Source: Internet
Author: User
Very useful php prevents SQL injection vulnerability filtering function code

  1. // PHP full-site anti-injection program, which must be included in the public file require_once
  2. // Determine the magic_quotes_gpc status
  3. If (@ get_magic_quotes_gpc ()){
  4. $ _ GET = sec ($ _ GET );
  5. $ _ POST = sec ($ _ POST );
  6. $ _ COOKIE = sec ($ _ COOKIE );
  7. $ _ FILES = sec ($ _ FILES );
  8. }
  9. $ _ SERVER = sec ($ _ SERVER );
  10. Function sec (& $ array ){
  11. // If it is an array, traverse the array and call it recursively
  12. If (is_array ($ array )){
  13. Foreach ($ array as $ k => $ v ){
  14. $ Array [$ k] = sec ($ v );
  15. }
  16. } Else if (is_string ($ array )){
  17. // Use the addslashes function for processing
  18. $ Array = addslashes ($ array );
  19. } Else if (is_numeric ($ array )){
  20. $ Array = intval ($ array );
  21. }
  22. Return $ array;
  23. }
  24. // Integer filter function
  25. Function num_check ($ id ){
  26. If (! $ Id ){
  27. Die ('parameter cannot be blank! ');
  28. } // Whether it is null
  29. Else if (inject_check ($ id )){
  30. Die ('invalid parameter ');
  31. } // Injection judgment
  32. Else if (! Is_numetic ($ id )){
  33. Die ('invalid parameter ');
  34. }
  35. // Digital judgment
  36. $ Id = intval ($ id );
  37. // Integer
  38. Return $ id;
  39. }
  40. // Character filtering function
  41. Function str_check ($ str ){
  42. If (inject_check ($ str )){
  43. Die ('invalid parameter ');
  44. }
  45. // Injection judgment
  46. $ Str = htmlspecialchars ($ str );
  47. // Convert html
  48. Return $ str;
  49. }
  50. Function search_check ($ str ){
  51. $ Str = str_replace ("_", "\ _", $ str );
  52. // Filter out "_"
  53. $ Str = str_replace ("%", "\ %", $ str );
  54. // Filter out "%"
  55. $ Str = htmlspecialchars ($ str );
  56. // Convert html
  57. Return $ str;
  58. }
  59. // Form filter function
  60. Function post_check ($ str, $ min, $ max ){
  61. If (isset ($ min) & strlen ($ str) <$ min ){
  62. Die ('minimum $ min Byte ');
  63. } Else if (isset ($ max) & strlen ($ str)> $ max ){
  64. Die ('maximum $ max Byte ');
  65. }
  66. Return stripslashes_array ($ str );
  67. }
  68. // Anti-injection function
  69. Function inject_check ($ SQL _str ){
  70. Return eregi ('select | inert | update | delete | \ '| \/\ * | \. \. \/| \. \/| UNION | into | load_file | outfile ', $ SQL _str );
  71. // Filter and prevent injection
  72. }
  73. Function stripslashes_array (& $ array ){
  74. If (is_array ($ array )){
  75. Foreach ($ array as $ k => $ v ){
  76. $ Array [$ k] = stripslashes_array ($ v );
  77. }
  78. } Else if (is_string ($ array )){
  79. $ Array = stripslashes ($ array );
  80. }
  81. Return $ array;
  82. }
  83. ?>

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.