RE: [PHP] Simple Security
| From: | Jason Murray | Date: | Mon, 11 Sep 2000 07:07:22 +0000 |
| Subject: | RE: [PHP] Simple Security | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-16122@lists.php.net to get a copy of this message | ||
> I was wondering how secure is creating an html form that passes a name
> along to a php file that says something like:
> <?php
> if ($realname =="Andrew" or $realname == "andrew") {
> echo "<P><hr 6>";
> echo "<center><b>Welcome Andrew</b></center>";
> echo "The Information Entered into this Test Form Was: <br>";
> etc............
> Is something like that fairly easy to hack into, or is fairly
> secure? I am thinking the problem with that method is someone can just
> view that directory and download the php file and then view it. So is
there
> a better simple way to just create a barrier to getting to certain pages?
The security depends entirely on what its used for. If all your script is
doing
is accepting a name as input from a user and echoing it back to them, I
wouldn't
care if someone tried to make the script echo something I didn't enter.
However, if your script accepts (for example) an ID number, which relates to
an order ID in a database, and you're going to show the user the contents of
the order, then you'd be best to make sure that the user in fact owns the
order
before you show them, and stuff like that.
In short, your example doesn't require much security, but has the typical
level
of "security" that a form has. You'll probably see the user's input on the
URL
line if your form feeds back as a METHOD=GET (or no method specified), which
you
won't want to do in the case of a username and password. You *can* tell if
the
user sent a variable as a GET or a POST variable though, so if your form
functions
as a POST and someone tries to fool it with a GET, you'll know about it.
Jason
(in full-tilt ramble mode)