What's the best, Escape then store Or store then escape the output?

Posted by Axel on Stack Overflow See other posts from Stack Overflow or by Axel
Published on 2010-04-01T23:47:24Z Indexed on 2010/04/01 23:53 UTC
Read the original article Hit count: 245

Filed under:
|
|
|
|

Hi, After doing a long search on stackoverflow i didn't find any one talked about this even if it's a big choice, the Question is what's the best in order to prevent both of XSS and SQL injection, Escaping the data then store it in the DB or Store it as it is and escape when output it?

Note: it is better if you give some examples of practics if possible.

Thanks

© Stack Overflow or respective owner

Related posts about php

Related posts about mysql