sprintf , . sprintf , , PHP. sprintf , %s:
$str = implode('', range("\x00", "\xFF")); // string of characters from 0x00 – 0xFF
var_dump(sprintf("'%s'", $str) === "'".$str."'"); // true
, , ( MySQL, , youre MySQL), **mysql_real_escape_string**:
$myq = sprintf("select user from table where user='%s'", mysql_real_escape_string($_POST["user"]));