im not a big fan of sql real escape...we know that the var should not have any sql...a smple regx should tell us if there is any non expected char, just discard the bad input with a nasty response.