Skip to main content

Validate url parameters in php


I have rules in my .htaccess for pages, show property id etc...



I want to make sure I validate every parameter I get to the right query im getting.



I have:




RewriteRule ^(.*)$ page.php?page=$1
RewriteRule ^property/(.*)$ property.php?pid=$1



so in my php I do:




$page = $_GET['page'];



and




$propertyid = $_GET['pid'];



Now I need to secure them but I want to know which method is best to use to secure these and that is where im lost.


Source: Tips4allCCNA FINAL EXAM

Comments

  1. I would say to use these rules:

    RewriteRule ^([a-z0-9]+)/?$ page.php?page=$1 [L,NC]
    RewriteRule ^property/([0-9]+)/?$ property.php?pid=$1 [L,NC]


    this way if someone enters any characters other than letters and numbers (for pages) and numbers (for property) it will show a page not found.

    If you want really to be sure, you can

    $page = mysql_real_escape_string($_GET['page']); just make sure your database connection is open and you can cast the pid like $propertyid = (int)$_GET['pid'];

    ReplyDelete
  2. i think with page parameter you should have a list of acept pages, then after get 'page', you check if 'page' is in accept list.
    For example :

    $arr_pages = ('page1','page2','page3');
    $page = $_GET['page'];
    if(in_array($page,$arr_pages))
    {
    // do some thing
    }
    else
    {
    // page not found
    }


    And id :

    $propertyid = intval($_GET['pid']);


    hope this help :)

    ReplyDelete

Post a Comment

Popular posts from this blog

Why is this Javascript much *slower* than its jQuery equivalent?

I have a HTML list of about 500 items and a "filter" box above it. I started by using jQuery to filter the list when I typed a letter (timing code added later): $('#filter').keyup( function() { var jqStart = (new Date).getTime(); var search = $(this).val().toLowerCase(); var $list = $('ul.ablist > li'); $list.each( function() { if ( $(this).text().toLowerCase().indexOf(search) === -1 ) $(this).hide(); else $(this).show(); } ); console.log('Time: ' + ((new Date).getTime() - jqStart)); } ); However, there was a couple of seconds delay after typing each letter (particularly the first letter). So I thought it may be slightly quicker if I used plain Javascript (I read recently that jQuery's each function is particularly slow). Here's my JS equivalent: document.getElementById('filter').addEventListener( 'keyup', function () { var jsStart = (new Date).getTime()...

Is it possible to have IF statement in an Echo statement in PHP

Thanks in advance. I did look at the other questions/answers that were similar and didn't find exactly what I was looking for. I'm trying to do this, am I on the right path? echo " <div id='tabs-".$match."'> <textarea id='".$match."' name='".$match."'>". if ($COLUMN_NAME === $match) { echo $FIELD_WITH_COLUMN_NAME; } else { } ."</textarea> <script type='text/javascript'> CKEDITOR.replace( '".$match."' ); </script> </div>"; I am getting the following error message in the browser: Parse error: syntax error, unexpected T_IF Please let me know if this is the right way to go about nesting an IF statement inside an echo. Thank you.