MySQL injection protection and vulnerability signs using PHP
问题 What are the best ways to protect from MySQL injection? What are weaknesses I should look out for? I know what it is, but I really have no idea how vulnerable I might be. Though I have taken (what I think to be) steps toward protecting myself and my database. Is there any sure-fire way of stopping someone? BTW...I write in PHP:) 回答1: Use prepared statements instead of mixing the statement and the actual payload data. see http://dev.mysql.com/tech-resources/articles/4.1/prepared-statements