最终的清洁/安全功能
$_GET
$_POST
mysql_real_escape_string($_GET['var'])
..
$_GET
/$_POST
cleanMe($input)
mysql_real_escape_string
, htmlspecialchars
, strip_tags
, stripslashes
$input
.
$_GET
$_POST
$_GET = cleanMe($_GET);$_POST = cleanMe($_POST);
$_GET['blabla']
$_POST['haha']
function cleanMe($input) { $input = mysql_real_escape_string($input); $input = htmlspecialchars($input, ENT_IGNORE, 'utf-8'); $input = strip_tags($input); $input = stripslashes($input); return $input;}
红颜莎娜
江户川乱折腾
扬帆大鱼