Anti Sql Injection Protection

the newier version of the anti injection is in the mutoolz xmas version ... it has GET protection now.,. coz some people actually program with GET variables.

after i get sober ill will make a new thread with a new schema of protection for PHP websites.. yet another tutorial.. i have been using this,. so i guess it is very protected.
 
Re: [Guide] Anti Sql Injection Protection

if (stristr($_SERVER['HTTP_REFERER'], 'http://www.supamu.info') === FALSE ) {
die ( 'Hacking attempt. Your are such a Nooby!.. ' );
**
You can spoof your refferal headers to anything now a days :)
 
I have a problem with the code you provided.


Warning: session_destroy() [function.session-destroy]: Trying to destroy uninitialized session in ...
 
If you rely upon stored data it may potentially be tainted, code should be using mysql_real_escape_string() (but not addslashes() which is insufficient). This provides limited protection to simple SQL injections, but is the absolute minimum required for all applications trying to use the native database interfaces.
 
this one will block MUsqltools 2.1 ? because its connect by using IP
 
Dont like lazy guides :sleep: where to put exactly the code for SQL injections cuz from ur explanation -> "Put these on the top of the page just after <?" i didnt get much ,also do i have the atached file "sql_inject.dll" copy to folder where php.ini is?
 
Back