coba mysql_real_escape_string(). harus bekerja! http://php.net/manual/en/function .mysql-real-escape-string.php