$message = trim($_POST['new_posts']);
$message=str_replace('\\','\\\\',$message);
$message=addCslashes($message, '_%');
$searchData = mysql_real_escape_string($message); /// SQL inection
$search_mode = mysql_query("SELECT * FROM bot_boltun WHERE vopros LIKE '%".$searchData."%' ;");
while($result_mode = mysql_fetch_array($search_mode))
///// верно ли сверяю или косячу ?
if($result_mode['vopros'] == "$searchData")
{
echo "<br>".$result_mode['nik']." = ".$value_random." ".$result_mode['vopros'];
}
}