Re: Site Security

From: Date: Thu, 06 Nov 2003 14:54:22 +0000
Subject: Re: Site Security
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-168728@lists.php.net to get a copy of this message
"Shaun" <shaun@mania.plus.com> wrote in message news:20031106102322.62152.qmail@pb1.pair.com... > > "Dan Joseph" <djoseph@duhq.us> wrote in message > news:GHEOLLAIKHCPIJMHLDCGAEJMDCAA.djoseph@duhq.us... > > Hi, > > > > > > > I have created a site that allows users to schedule staff, make > > > appointments > > > etc. Users must log in to use the site and the users data is held in the > > > Users table of the MySQL database. However, due to the nature of > > > the site I > > > need to make sure it is 110% secure against hacks etc. Now I know > > > this isn't > > > actually possible but I would appreciate any advice on how I can get it > as > > > secure as possible, I have no experience on this aspect of web > > > development. > > > > Turn off register globals. Validate all form posts for bogus data. Check > > that the cookie hasn't been changed with bad characters malliciously. > > Things like that. Try and break into the site w/o logging in. We paid > for > > a security audit from a company called @stake (www.atstake.com). If you > can > > afford it, I'd contract someone to audit you. > > > > -Dan Joseph > > Thanks for your reply, > > why would it be necessary to turn off register globals? How could a cookie be changed maliciously? We use sessions anyway so this isn't an issue but I am curious to know :)

« previous php.general (#168728) next »