Re: Secuirity issues?

From: Date: Wed, 15 Nov 2000 20:14:49 +0000
Subject: Re: Secuirity issues?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-25517@lists.php.net to get a copy of this message
On Wed, 15 Nov 2000, Lauri Vain wrote: > Hello, > What is a bad thing to miss (that could become a secuirity issue) while writing > some PHP/SQL code? > > I figure that I shouldn't put my config.inc.php (containing SQL passes) files in > a publically readable dir because people could use include() to get the > password. > The fix? Putting config.inc.php files outside of the web tree? Using a .htaccess > file in the .in dir? > > Will PHP execute the PHP/SQL code inserted in text boxes? I've heard it does, > will it be fixed when I use just the addslashes() or will I need to use > something more? How about the escapeshellcmd(), should I use this too? > > Does anybody know more about writing "secure" PHP scripts? > > Yours, > Lauri > General security issues: 1) Turn register_globals off and use $HTTP_*_VARS instead. 2) Store passwords in a hashed format on the SB side. 3) Use sessions to store data instead of cookies. include() only works if it can see the php code. If you include() a remote script that doesn't print anything, well, it includes nothing. That's more of an issue for local scripts and users. Securing the file with .htaccess might be useful nonetheless. PHP won't execute any PHP code stored in variables unless you tell it to explicitly. It will, however, show HTML/CSS/JavaScript/JScript/VBScript code if the variable is printed out. Use htmlentities() or htmlspecialchars() for this. -- Ignacio Vazquez-Abrams <ignacio@openservices.net>

« previous php.general (#25517) next »