Was ist sicherer?
PHP Code:
<?php
function anti_injection($sql) {
$sql = preg_replace(sql_regcase("/(from|select|insert|delete|where|drop table|show tables|#|\*|--|\\\\)/"),"",$sql);
$sql = trim($sql);
$sql = strip_tags($sql);
$sql = addslashes($sql);
return $sql;
}
$username = anti_injection($_POST["username"]);
//...mysql_query usw...
?>
PHP Code:
<?php
$username = mysql_real_escape_string($_POST["username"]);
//...mysql_query usw...
?>
Freue mich schon...
mfg, ooCheateroo






