Security: PHP: how to "harden" PHP scripts?
| From: | Jean-Christian Imbeault | Date: | Wed, 03 Jul 2002 13:36:05 +0000 |
| Subject: | Security: PHP: how to "harden" PHP scripts? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-105183@lists.php.net to get a copy of this message | ||
I'm writing my first commercial site and of course I am thinking about security. I'm worried about someone using a flaw in my PHP script logic to access information they shouldn't.
I've read the PHP books I have and Googled around but can't quite find specific answers to my questions about PHP and security.
In general how does one go about hardening a PHP script. i.e. making it as "hacker-proof" as possible. General things like:
- verifying user inputted data
- not putting clear-text passwords in php scripts
- use "safe-mode"?
And specifically, what are some things one can do? Things like:
- use addslashes with user data
- use mysql_escape_string for data submitted to mysql
Thanks,
Jc