mysql_real_escape_string() / mysqli_real_escape_string() Louis Solomon www.SteelBytes.com -----Original Message----- From: Jacob Kruger [mailto:jacobk@xxxxxxxxxxxxxx] Sent: Wednesday, 5 August 2009 2:58 PM To: php-windows@xxxxxxxxxxxxx Subject: Relatively simple PHP function to block sql injection Haven't gotten around to really looking for this too much, and currently really only replace any single 's with double ones before performing an insert into MySQL, but was just wondering if there are any 'standard' PHP functions out there that get used to block any form of attempted sql injection? TIA Jacob Kruger Blind Biker Skype: BlindZA '...fate had broken his body, but not his spirit...' __________ Information from ESET NOD32 Antivirus, version of virus signature database 4306 (20090804) __________ The message was checked by ESET NOD32 Antivirus. http://www.eset.com -- PHP Windows Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php