Announcement

Collapse
No announcement yet.

If you code in PHP, and/or use Databases, READ THIS NOW!

Collapse
This is a sticky topic.
X
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • If you code in PHP, and/or use Databases, READ THIS NOW!

    I happened across this article while researching PHP Security. It has some of the most important information a programmer could ever need, and is a must read for anyone who is just beginning to program or is a seasoned veteran.

    http://www.addedbytes.com/security/writing-secure-php
    ---> Section 1 has 3 sub-sections
    http://www.addedbytes.com/security/writing-secure-php-2
    ---> Section 2 has 3 sub-sections
    http://www.addedbytes.com/security/writing-secure-php-3
    ---> Section 3 has 5 sub-sections
    Last edited by Pegasus; 06-03-2009, 02:24 PM. Reason: new domain

  • #2
    Thanks for sharing, very interesting articles. I'll make note of it for the future.

    Comment


    • #3
      Good post Chad, I will add it to the php faq in this forum. Although it is a old article it still provides valuable security tips.
      Have a Script or Snippet you want to share?

      WWW Standards: HTML 4.01,
      HTML 5, CSS2.1, CSS3, XHTML 1.0
      PHP Standards: PHP Standards

      Comment


      • #4
        Very nice, tried to hack my own site to see if I had vulnerabilities, but got nowhere, but I'm really only using phpBB and cpanel so theres not much to hack.

        Comment


        • #5
          surprising as phpBB was one of the biggest hole makers lol
          Have a Script or Snippet you want to share?

          WWW Standards: HTML 4.01,
          HTML 5, CSS2.1, CSS3, XHTML 1.0
          PHP Standards: PHP Standards

          Comment


          • #6
            great read Chad! thank you

            Comment


            • #7
              Great links! Ive been trying to make my larger applications a little more secure.

              Comment


              • #8
                Nice articles for beginning php/mysql developers! A must-read if you don't have php security knowledge yet..

                Maybe the author should give it an update, as some things are outdated (i.e. the register globals 'problem'/'possible hole')

                Comment


                • #9
                  Points to sig... I guess no one noticed

                  Comment


                  • #10
                    Excellent post, Chad. Thank you for that.

                    Comment


                    • #11
                      Excellent find. Here is another site I found that has some more things you should disable in your php.ini file for better security:

                      http://www.claroline.net/wiki/index.php/Security

                      It makes me sleep better at night knowing there is added security to my site . I combined things to disable from jack daniels and this site I found with some examples of how to disable the bad features of PHP entirely. I know my sites not huge, but you can't trust any of your users as JD's site says.

                      Comment


                      • #12
                        i hate those god damn users. I'll ban them all
                        SANITY IS JUST A STATE OF MIND

                        Comment


                        • #13
                          Old thread o_0

                          Comment


                          • #14
                            Originally posted by erisco View Post
                            Old thread o_0
                            so, good information and I am glad he brought it back to the top.
                            Have a Script or Snippet you want to share?

                            WWW Standards: HTML 4.01,
                            HTML 5, CSS2.1, CSS3, XHTML 1.0
                            PHP Standards: PHP Standards

                            Comment


                            • #15
                              Maybe you should sticky it, then.

                              Comment

                              Working...
                              X