Re: SQL injection - mysql_real_escape_string()?

Ariz Jacinto <[email protected]>
Newsgroups gmane.comp.php.windows
Message-ID <CA+rqb_3RKt6s7_y_DexPHDnQzHvi4502GNKzxpGQo8qpQgzBnA@mail.gmail.com>
Hi Jacob,

Yes, you need to do more than just using mysql_real_escape_string()
solely. I recommend the book "SQL Antipatterns: Avoiding the Pitfalls
of Database Programming" by Bill Karwin

http://www.amazon.com/SQL-Antipatterns-Programming-Pragmatic-Programmers/dp/1934356557

-- 
PHP Windows Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.