Re: Help with security please
Anything being queried into mySQL should be mres (mysql_real_escape_string();) and anything which is being showed somewhere (Name, Display Pic, Signature, Shoutbox area, Mail and so on) should be htmlentities();'d Theres other security methods but these seem to work quite well.