Re: Security Issue Query.......

From: Date: Wed, 06 Sep 2000 04:37:03 +0000
Subject: Re: Security Issue Query.......
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-15430@lists.php.net to get a copy of this message
Kenneth Bogucki wrote: > Security Issue Query....... > Having read the bulk of the posts over the last several days, re: > security issues, I find myself in a state of confusion. > I've got four sites going up in the next two months and have moved all > of them over to php with MySQL. I've taken what I believe are the usual > security steps..now what I believe may not be true. > My question is: anyone have a url for a site that deals with security > issues, particularly as these issues relate to php...I'm working off a > hosting service...which may complicate matters. Unfortunately I'm not aware of an all encompasing PHP security site. Personally I think there is a big need for a much better security documentation with respect to PHP. Docs which pull together PHP issues as well as more general web development security issues. Perhaps linking out to important advisories on certain areas. Advisories like... SQL Security : "How I hacked PacketStorm" http://www.wiretrip.net/rfp/p/doc.asp?id=42&iface=2 Cross Site Scripting http://www.cert.org/advisories/CA-2000-02.html Don't trust form variables or the Refferer field http://xforce.iss.net/alerts/advise42.php Watch that server config, this affects PHP too. http://www.mail-archive.com/bugtraq%40securityfocus.com/msg02780.html there are heaps more of course. -- Simon Edwards Animated Design, Melbourne http://www.animated.net.au/ Ph: (03) 98850990

« previous php.general (#15430) next »