$re = '/(?:INSERT INTO|UPDATE|SELECT|DELETE)(?:[^;\'"]|(?:\'[^\']*?\')|(?:"[^"]*?"))+;/i';
$str = 'String query = "select * from users_table where username = \'" + u_username + "\' and password = \'" + u_password +"\';";
String query2 = "select * from users_table where username = \'" + u_username + "\' and password = \'" + u_password +"\'";
SQLiteDatabase db
//some un-important code here...
Cursor c = db.rawQuery( p_query, null );
return c.getCount() != 0;
}';
preg_match_all($re, $str, $matches, PREG_SET_ORDER, 0);
// Print the entire match result
var_dump($matches);
Please keep in mind that these code samples are automatically generated and are not guaranteed to work. If you find any syntax errors, feel free to submit a bug report. For a full regex reference for PHP, please visit: http://php.net/manual/en/ref.pcre.php