为了赢得避免卡片注射攻击,I m 期待着清理我的网站用户输入的所有文本(和大多数其他数据),然后将其输入储存数据库。
I was under the impression that the function inserted backslashes ( ) before all characters capable of being malicious ( , , " , etc ), and expected that the returned string would contain the newly added backslashes.
我对载有这种潜在恶性特征的编织物进行了简单测试,并对该文件作了回应,确切地看到了我所期望的一点:用斜坡来扼杀这些特性。
因此,我着手在数据中添加清理功能,然后储存到数据库中。 我在为数据储存而建造的询问中加入(Msqli_real_einski_string(链接,显示美元)。 我很惊讶地测试了该书,我(对我方略)注意到,数据库中储存的数据似乎并未包含斜坡。 我测试、测试和测试,但都没有结果,一米损失。
Any suggestions? Am I missing something? I was expecting to then have to remove the backslashes with the stripslashes($string) function, but there doesn t seem to be anything to strip...