http://www.php.net/htmlentities
http://www.php.net/mysql_escape_string