RE: [PHP] Simple Security

From: Date: Mon, 11 Sep 2000 07:07:22 +0000
Subject: RE: [PHP] Simple Security
Groups: php.general 
Request: Send a blank email to php-general+get-16122@lists.php.net to get a copy of this message
> I was wondering how secure is creating an html form that passes a name > along to a php file that says something like: > <?php > if ($realname =="Andrew" or $realname == "andrew") { > echo "<P><hr 6>"; > echo "<center><b>Welcome Andrew</b></center>"; > echo "The Information Entered into this Test Form Was: <br>"; > etc............ > Is something like that fairly easy to hack into, or is fairly > secure? I am thinking the problem with that method is someone can just > view that directory and download the php file and then view it. So is there > a better simple way to just create a barrier to getting to certain pages? The security depends entirely on what its used for. If all your script is doing is accepting a name as input from a user and echoing it back to them, I wouldn't care if someone tried to make the script echo something I didn't enter. However, if your script accepts (for example) an ID number, which relates to an order ID in a database, and you're going to show the user the contents of the order, then you'd be best to make sure that the user in fact owns the order before you show them, and stuff like that. In short, your example doesn't require much security, but has the typical level of "security" that a form has. You'll probably see the user's input on the URL line if your form feeds back as a METHOD=GET (or no method specified), which you won't want to do in the case of a username and password. You *can* tell if the user sent a variable as a GET or a POST variable though, so if your form functions as a POST and someone tries to fool it with a GET, you'll know about it. Jason (in full-tilt ramble mode)

« previous php.general (#16122) next »