Re: Site Security
| From: | Shaun | Date: | Thu, 06 Nov 2003 14:54:22 +0000 |
| Subject: | Re: Site Security | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-168728@lists.php.net to get a copy of this message | ||
"Shaun" <shaun@mania.plus.com> wrote in message
news:20031106102322.62152.qmail@pb1.pair.com...
>
> "Dan Joseph" <djoseph@duhq.us> wrote in message
> news:GHEOLLAIKHCPIJMHLDCGAEJMDCAA.djoseph@duhq.us...
> > Hi,
> >
> >
> > > I have created a site that allows users to schedule staff, make
> > > appointments
> > > etc. Users must log in to use the site and the users data is held in
the
> > > Users table of the MySQL database. However, due to the nature of
> > > the site I
> > > need to make sure it is 110% secure against hacks etc. Now I know
> > > this isn't
> > > actually possible but I would appreciate any advice on how I can get
it
> as
> > > secure as possible, I have no experience on this aspect of web
> > > development.
> >
> > Turn off register globals. Validate all form posts for bogus data.
Check
> > that the cookie hasn't been changed with bad characters malliciously.
> > Things like that. Try and break into the site w/o logging in. We paid
> for
> > a security audit from a company called @stake (www.atstake.com). If you
> can
> > afford it, I'd contract someone to audit you.
> >
> > -Dan Joseph
>
> Thanks for your reply,
>
> why would it be necessary to turn off register globals?
How could a cookie be changed maliciously? We use sessions anyway so this
isn't an issue but I am curious to know :)