RE: [PHP] <form> security problem
| From: | Bruin, Bolke de | Date: | Fri, 13 Oct 2000 19:25:39 +0000 |
| Subject: | RE: [PHP] <form> security problem | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-20066@lists.php.net to get a copy of this message | ||
First rule in security matters:
Never trust user input.
You should always check any user input though a database or alikes.
like when you are having a guestbook system with admins.
in the form you put a unique identifier and through a cookie or a submitted
password you check in the database if
the password is right for that identifier.
Bolke
-----Original Message-----
From: Vojtech Patrný [mailto:patrnyv@yahoo.com]
Sent: vrijdag 13 oktober 2000 18:52
To: php-general@lists.php.net
Subject: [PHP] <form> security problem
Hi,
I`ve a problem with my php app.
I use this code :
(form action="a.php")
(input name="test" type="text" value="0")
(input type="submit")
(/form)
The problem is that anybody can save this page on
his computer and edit the value="xx" and then send
it to my DB. I need to filter if it cames from my site.
Can somebody help me please?
Data in value change every time so it`s
imposible to make a db filter.
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net