Re: Security Issue Query.......
| From: | Simon Edwards | Date: | Wed, 06 Sep 2000 04:37:03 +0000 |
| Subject: | Re: Security Issue Query....... | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15430@lists.php.net to get a copy of this message | ||
Kenneth Bogucki wrote:
> Security Issue Query.......
> Having read the bulk of the posts over the last several days, re:
> security issues, I find myself in a state of confusion.
> I've got four sites going up in the next two months and have moved all
> of them over to php with MySQL. I've taken what I believe are the usual
> security steps..now what I believe may not be true.
> My question is: anyone have a url for a site that deals with security
> issues, particularly as these issues relate to php...I'm working off a
> hosting service...which may complicate matters.
Unfortunately I'm not aware of an all encompasing PHP security site.
Personally I think there is a big need for a much better security
documentation with respect to PHP. Docs which pull together PHP issues
as well as more general web development security issues. Perhaps linking
out to important advisories on certain areas. Advisories like...
SQL Security : "How I hacked PacketStorm"
http://www.wiretrip.net/rfp/p/doc.asp?id=42&iface=2
Cross Site Scripting
http://www.cert.org/advisories/CA-2000-02.html
Don't trust form variables or the Refferer field
http://xforce.iss.net/alerts/advise42.php
Watch that server config, this affects PHP too.
http://www.mail-archive.com/bugtraq%40securityfocus.com/msg02780.html
there are heaps more of course.
--
Simon Edwards
Animated Design, Melbourne
http://www.animated.net.au/ Ph: (03) 98850990