On Fri, Mar 18, 2005 at 10:57:34AM -0500, Peter Jay Salzman wrote: > > http://www.dirac.org/linux/sql_quoting.html The PHP magic quote thing seems rather retarded, but I think that you've basically arrived at the correct conclusion: Always use the database API's method for escaping special characters -David