View Single Post
Old 08-22-2004, 08:53 AM   #1 (permalink)
Fallon
Junkie
 
Location: RI
[C] Preventing SQL Injection

k, so I'm running a MUD with a MySQL backend and I've had a total brain fart. I'm trying to write a function that'll check the string going to the db to make sure that it doesn't contain any nasties in it that'll cause the db to go boom. I've tried strchr to check for a ;. I've thought about comparing, but that won't work because I just need it to get one dinky little part. Any idea on how I can do this? Thanks.
Fallon is offline  
 

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47