$pattern='/\*/'; $searchword=preg_replace ( $pattern , '%', $_GET['word']); //will let the use of asterisk symbol //Here goes addslashes or some preg_replace function to make the query SQL-injections-safe if ($tmp=mysql_query("SELECT charName, charId from characters where charName LIKE '$searchword';")) { echo 'search results:<br />'; while ($result=mysql_fetch_array($tmp)) { echo '<a href="/vtdb/char.php?'.$result['charId'].'">'.$result['charName'].'</a><br />'; } } else { echo "no result"; }