3 ms·
Honestly, I wouldn't even suggest people try and escape their inputs. Just use parameters. They will be far more secure than attempting to escape and sanitize i
by JasonCannon 5y ago
Honestly, I wouldn't even suggest people try and escape their inputs. Just use parameters. They will be far more secure than attempting to escape and sanitize inputs.
- _ndianabasi 5y agoI agree as well. I suggested using parameters/bindings. Hope you saw that in the article. Thank you for your comment.
- JasonCannon 5y agoI did see that, I was saying skip the first suggestion of sanitizing input, and just use the second suggestion. The first suggestion is just asking for trouble.
- geoduck14 5y agoThis advice doesn't sit right with me. I like to make sure my numbers don't contain chars. But that is about not breaking my data flow- not security.
- JasonCannon 5y agoSure, I'm not talking about no validation or sanitation. I'm talking about as a security measure. Trust the far more secure parameters rather than thinking that escaping some quotes is going to protect you.
- _ndianabasi 5y agoThat's the purpose of validation. I think we was talking about sanitisation before storage. But I think that if there is a good validation, sanitisation is half taken care of. Sanitisation will still be indispensable even if one is using parameter bindings or prepared statements.