Featured post

c# - Usage of Server Side Controls in MVC Frame work -

i using asp.net 4.0 , mvc 2.0 web application. project requiremrnt have use server side control in application not possibl in noraml case. ideally want use adrotator control , datalist control. i saw few samples , references in codepleax mvc controllib howwver found less useful. can tell how utilize theese controls in asp.net application along mvc. note: please provide functionalities related adrotator , datalist controls not equivalent functionalities thanks in advace. mvc pages not use normal .net solution makes use of normal .net components impossible. a normal .net page use event driven solution call different methods service side mvc use actions , view completly different way handle things. also, mvc not use viewstate normal .net controlls require. found article discussing mixing of normal .net , mvc.

php - Parameterized Query -


pls code secure?

/* create new mysqli object database connection parameters */ $mysqli = new mysql('localhost', 'username', 'password', 'db');  if(mysqli_connect_errno()) { echo "connection failed: " . mysqli_connect_errno(); exit(); }  /* create prepared statement */ if($stmt = $mysqli -> prepare("select priv testusers username=? , password=?")) {  /* bind parameters s - string, b - boolean, - int, etc */ $stmt -> bind_param("ss", $user, $pass);  /* execute */ $stmt -> execute();  /* bind results */ $stmt -> bind_results($result);  /* fetch value */ $stmt -> fetch();  echo $user . "'s level of priviledges " . $result;  /* close statement */ $stmt -> close(); }  /* close connection */ $mysqli -> close(); 

as far protection against mysql injection concerned: yes. mysqli's parametrized queries safe against injection attacks.

if $user comes external source, may want add htmlentities() echo statement prevent users signing user name <script>(some malicious code)</script>


Comments

Popular posts from this blog

c# - Usage of Server Side Controls in MVC Frame work -

cocoa - Nesting arrays into NSDictionary object (Objective-C) -

ios - Very simple iPhone App crashes on UILabel settext -