me if I am
wrong, I am by no means a security or PHP expert, though working towards
both :D)
On Saturday 17 June 2006 14:51, Anthony Ettinger wrote:
> simply using $_POST is by no means more secure than $_REQUEST.
>
> On 6/17/06, Ben Ramsey <[EMAIL PROTECTED]> wrote:
> > On 6/
intend.
So, there are two things you must do here: 1) always check the origin of
your data (don't use $_REQUEST, even if it seems convenient), and 2)
always check that the input received is input expected (filter the input).
--
Ben Ramsey
http://benramsey.com/
--
PHP General Mailing Li
k/dg/insp>
Cool sites btw! Good work. :)
Cheers,
M
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
I'ts been awhile, but try the above.
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
tables?
Kindly suggest with pros and cons of each.
you might want to consider storing the files outside of the database
as well, and just a pointer to it's path in the table.
with respect to table vs. databases per user, neither.
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.
On 6/7/06, tedd <[EMAIL PROTECTED]> wrote:
Can someone shed some light on this for me? How can one do sessions and make
Google bots happy?
I think what they're getting at is don't use session id's unless
they're logged in.
--
Anthony Ettinger
Signature: http://c
of web-based application development
> - GETs get, POSTs do.
Add
Ticket
Just change enqno= for a different queue.
Found the simple answer - Double click - two records !
Like the previous poster says, GET requests should not "put, they
should only "get". Use POST to writ
ger Download now
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
ll LiveHTTPHeaders in Firefox and see what Cookies you get.
Configure your browser to prompt you for all Cookies and see what
Cookies you get.
HTH
mediawiki.org
#mediawiki on irc.freenode.net
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
ot to mention that all the "good" matching possible delimiters are
already taken for Arrays, code blocks, tag start/end, and order of
operations.
--
Like Music?
http://l-i-e.com/artists.htm
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.ph
rt now
[/aha moment]
http://www.organicseo.org/URL_Rewriting.html
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
ve no sympathy for you when, when, not if, when your server is
trashed. Sorry.
--
Like Music?
http://l-i-e.com/artists.htm
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.h
alize() to do a dump, I get this error.
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
isn't really what I want.
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
),
bar2 => array (...),
barN => array(...),
);
would want the output to be something like:
Some Title
Some Text
Some Title2
Some Text2
...
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
ed)
>
> This is what I have now, but I don't know what to call my {if ?}
>
> {if ?} src="{$ImagesDir}/arrow.gif" width="9" height="7" border="0"
> align="abstop">{$menu_content}
> {else}
> {$menu_content}
> {/
t (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
t; --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
really.
>
> oh and please don't post your questions directly at me unless:
>
> a, I ask you to.
> or b, I can bill you.
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
; Dan
>
> ---
> http://chrome.me.uk
>
>
> -Original Message-
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Anthony
> Ettinger
> Sent: 12 April 2006 00:58
> To: Chrome
> Cc: Mace Eliason; php-general@lists.php.net
> Subj
s message was checked by NOD32 antivirus system.
> http://www.eset.com
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
actually...
alert('');
On 4/11/06, Anthony Ettinger <[EMAIL PROTECTED]> wrote:
> alert('echo $errorMessage');
>
> On 4/11/06, Mace Eliason <[EMAIL PROTECTED]> wrote:
> > Hi,
> >
> > I am not sure why this won't work I am pretty
ed to screen
> echo"alert('$errorMessage');";
> }
>
> I am capturing all the errors from a form and then output them all at once
>
> Thanks for any help
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net
Systems Administrator
> > > American Student Loan Services
> > > www.americanstudentloan.com
> > > 1.800.575.1099
> > >
> >
> > --
> > PHP General Mailing List (http://www.php.net/)
> > To unsubscribe, visit: http://www.php.net/unsub.php
> >
> >
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
c/controller/Controller.php on line 27
>
> But, the file that I pass to require_once exist in the server...
> If someone know the problem, please sende a answer...
>
> Thank you,
>
> Pablo
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
st (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
ail: [EMAIL PROTECTED]
> Web : http://www.hotelkey.com
> http://www.destinia.com
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.ht
gt; I was affraid :o from the news
> > >
> > > Rule #1 on the Internet... Never trust any news without a link to an
> > > official source
> > > Rule #2 on the Internet... Never trust anything you read on April 1st
> > >
> > > -Stut
> > &g
rld to get a web scripting language at a high
> > >>> entreprise level is now bought by Micrsoft ?
> > >> Where did you hear this? Have you considered the date? Have you
> > >> considered how unlikely it is? Have you ever sought professional
> help?
> > >>
> > >> -Stut
> >
> >
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
ly going to get you into
> > trouble.
>
> So you close it after every query and then re-open it later for the
> next query? I don't see that as a good idea.
>
No, you leave it open until you're done with the database.
If you pee and poo in one sitting, you don
would keep the connection open until
the script ends.
by closing it earlier when you're done with the database for the
"event", your script continues on, ie - parsing/displaying of db query
results, template rendering, etc. yet the connection was closed
earlier so other processes can use mysql (assuming your hitting your
limit this way with too many simultaneous connections).
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
nevermind, that doesn't work...after testing it :*(
i've seen it in perlregex.
On 3/31/06, Eduardo Raúl Galván Sánchez <[EMAIL PROTECTED]> wrote:
> Anthony Ettinger wrote:
> > ($a, $b) = $c;
> ^^ I don't get the meaning of this...
>
> >
> >
> [lat] => 29.216
> )
>
> [1] => Array
> (
> [lon] => -99.0618
> [lat] => 29.179
> )
> }
> }
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
tLabelClass &&
> > $readingGoalsInformationLabelClass &&
> > $readingGoalsAlphabeticLabelClass &&
> > $readingGoalsPrintLabelClass &&
> > $readingGoalsPhonologicalLabelClass &&
> > $readingGoalsPhoneticLabelClass &&
> > $readingGoal
>
> didn't test it, but this should work.
> [/snip]
>
> Didn't work, returns ArrayArray=ArrayArrayArray=ArrayArray=Array
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
t; And so on
>
> I am sure that it has something to do with my lack of sleep and the
> looming of deadlines and this being something that I thought would be
> trivial. Can someone drop-kick me in the right direction please? The sub
> arrays need to be the points in each of the ar
php5 still has the mysql_pconnect method for persistent database
connections:
http://us2.php.net/mysql_pconnect
--
> Postgresql & php tutorials
> http://www.designmagick.com/
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
from here:
> >
> > http://www.schlossnagle.org/~george/php/WSDL_Gen.tgz
> >
> > We did it using PHP5's soap extension.
> >
> > good luck!
> >
> > --
> > PHP General Mailing List (http://www.php.net/)
> > To unsubscribe, visit: http://www.php.net/unsub.php
> >
> >
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
erver.
Apache Server at foo.org Port 80
On 3/30/06, Jasper Bryant-Greene <[EMAIL PROTECTED]> wrote:
> In other words, if you want Firefox/Opera/etc to display something, you
> have to output something. Strange, that. :P
>
> Jasper
>
> Anthony Ettinger wrote:
> > T
Then it's workingFireFox, et. al. show you the server 404, IE on
the otherhand has it's own 404 error page (for those newbies who don't
know what a 404 is). You can disable it under IE options.
On 3/30/06, Bronislav Klucka <[EMAIL PROTECTED]> wrote:
> Yes, I do...
&
ent-Type: text/html
>
> 404 Not Found
> --
>
> can anyone tell me, why those two browsers are not affected?
>
> Brona
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anth
th-xslt-sablot
>
> I get no errors and PHP works fine, but i get no XSLT support (confirmed
> via phpinfo()).
>
> Any ideas ?
>
> Any help would be apreciated.
>
> Warm Regards,
> MA
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscr
de. I can't top that.
lol! that must've been before the wheel.
I remember when we got our first hard-drive in the lab...a 10Mb
> dishwasher sized behemoth with its own AC unit
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
the index.php of course loads into the div-tag with id=main. BUT
> when I press a topic or something within this page (index.php), it opens up
> in a new page. I know why, but I wonder if there is a way to get the rest of
> the links in the forum to stay within my div-tag other than tracking down
> all the variables and such in the forumscripts and alter them? (That's a
> hell of alot java and php to work through)
>
> Any help is appreciated.
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
On 3/28/06, M. Sokolewicz <[EMAIL PROTECTED]> wrote:
> Anthony Ettinger wrote:
> > On 3/28/06, Joe Henry <[EMAIL PROTECTED]> wrote:
> >
> >>On Tuesday 28 March 2006 1:12 pm, Jochem Maas wrote:
> >>
> >>> >>>
> >>>class
f = new Foo;
> > echo $f->foo,"\n";
> > $f->foo = "bar";
> > echo $f->foo,"\n";
>
> Maybe I'm wrong, but I thought you couldn't use the "$f->foo" to access
> private variables from outside a class?
I think h
On 3/28/06, Jochem Maas <[EMAIL PROTECTED]> wrote:
> Anthony Ettinger wrote:
> > On 3/28/06, Jay Blanchard <[EMAIL PROTECTED]> wrote:
> >
> >>[snip]
> >>I see this all over the place, but I don't think it stores the variable
> >>in =
>
within the class.
if you set private $foo = 'foo';
print $f->__getFoo();
$f->__setFoo('bar');
print $f->__getFoo();
Yields:
foo
bar
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
I see this all over the place, but I don't think it stores the variable in =
$foo:
class Foo {
private $foo;
public function __setFoo($arg)
{
$this->foo = $arg;
}
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.
>
> --
> Kevin Murphy
> Webmaster - Information and Marketing Services
> Western Nevada Community College
> www.wncc.edu
> (775) 445-3326
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
Just a gue
On 3/27/06, Anthony Ettinger <[EMAIL PROTECTED]> wrote:
> On 3/27/06, Ryan A <[EMAIL PROTECTED]> wrote:
> > Ooops, and lets not forget this one:
> >
> > curl http://www.yoursite.com/path/to/script/yourscript.php
> >
> > you can put that in your c
h
$ ls /etc/php
apache2-php4 apache2-php5 cli-php4
I don't think the binary php exists on my system.
The only php* binary matches I have are:
$ php
php-config phpize
I think cli-php4 is the command-line-interface php.ini file for php4,
but the binary is no longer on my system.
If anyone
#x27;t.
>
>
> How would you like to come across? As an ungrateful SOB who can't take some
> constructive critisism? You have some growing up to do before entering el
> big bad world. Babies these days...
>
> I'll add more to this tomorrow morning when I'm sober.
&g
which
> > would be ececuted on my server. Is that right? And if yes, what
> > can I do against it?
>
> Use readfile(), but remember that this allows him to inject anything he
> likes into the content you send users, so your passing your risk onto
> your users.
>
>
...or you may have to decode the html entities first.
On 3/21/06, Anthony Ettinger <[EMAIL PROTECTED]> wrote:
> saveHTML();?
>
> instead of saveXML();
>
> On 3/21/06, jonathan <[EMAIL PROTECTED]> wrote:
> > I'm interested in creating an xml doc from my php5/
ings/designmobile/
> http://www.opera.com/docs/specs/css/
>
> HTH's
>
> tedd
> --
>
> http://sperling.com
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, v
thanks,
>
> jonathan
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
On 3/16/06, Miles Thompson <[EMAIL PROTECTED]> wrote:
> At 05:40 PM 3/16/2006, Anthony Ettinger wrote:
>
> >dreamhost let's you choose php4 or 5, as I'm sure others do as well.
>
>
> A little more on dreamhost.
> PHP5 is installed as CGI, not Apache modul
ot install a cpoy of apache/php5/mysql/etc
> on your local PC and play with that?
>
> >
> > Thanks.
> >
> > tedd
> >
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
---
> http://sperling.com
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
that.
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
ape from php mode.
> ?>
>
>
>
>
> $QUERY_STRING;}?>" method="POST">
>
>
> Incorrect username and/or password. Please enter correct ones to log in:
>
>
>
>
> Username:
>
>
>
have 1 field for all countries, I believe the total is
23?
+011-049-069-13788-1234
--------
> http://sperling.com
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
t; server log and each time an e-mail has been sent to me of that kind
> there
> > is a logentry in apache log that says that this script has been
> executed.
> > So the e-mails definatelly come from that script?!
> >
> > Can anybody help?
> >
> > Regards, Merlin
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
ing? Might want to try \[\/url\], in most regex
engines "/" is used as the separater between the s/search/replace/si;
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
P5 - Objects, Patterns, and Best Practices (publisher apress)
http://tinyurl.com/ohybj
I just finished reading this book, it's an excellent source for OOP
with php5. Also includes common patterns, complete with UML diagrams,
something you rarely see in programming books, at least the ones I've
re
change the current behavior...easier to plan for that
ahead of time. Technically, it works the way you want it...there's no
right or wrong way, just degrees of flexibility, and it so happens
this method seems inflexible from what I gather.
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
ng List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
Not to mention adding other tables which references those numbers as a
foreign key. Seems like the wrong way to do it in my opinion. Business
logic should be abstracted from the database layer and
-
>
> I assume your loop is something like:
> while(condition) {
> $auction_parts['id'] = 'some value';
> $auction_parts['name'] = 'some value';
> ...
> $insert->execute();
> }
>
> My first guess would be, if n
;
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
Can you dump the error string reported back from the mysql database
connection? Could provide some insight as to why your INSERT fails,
and the UPDATE works.
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
ated with unique ids '2'
> through '5' were deleted during testing, and so on. So, they feel that
> 'user2' should have a unique id of '2', ignoring the fact that that's
> not a unique id at all, if you had id '2' associated with another record
> at some point.
>
> I'm not suggesting this is what the OP is doing, just that that's why I
> was curious about the purpose.
>
> Much warmth,
>
> planetthoughtful
> ---
> "Lost in thought"
> http://www.planetthoughtful.org
>
>
--
Anthony Ettinger
Signature: http://chovy.dyndns.org/hcard.html
not be what is not acurate enough. thank you for you help. simple fix. i
> > should have caught it.
> > - Original Message -
> > From: "Anthony Ettinger" <[EMAIL PROTECTED]>
> > To: "benifactor" <[EMAIL PROTECTED]>
> &
> --
> Regards
> Julius Hacker
>
> http://www.julius-hacker.de
> [EMAIL PROTECTED]
>
> OpenPGP-Key-ID: 0x4B4A486E
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
--
Anthony Ettinger
Signatur
n i_gun ($user) {
> global $username;
> $gun = mysql_query("select * from users");
> while ($d = mysql_fetch_array($gun)) {
> while($d[username] != $user) {
> $i = $i + 1;
> }
> }
> }
>
> but it always returns 1. can sombody tell me what i am doing wron
ure you validate all fields before
breaking out, track them in an $errors = array(); ...makes for a
better user experience.
Typically, there is a hidden field called "run" or "mode" indicating
what flow you're in.
Login
Username:
Password:
75 matches
Mail list logo