RE: [PHP] PHP Security

From: Date: Fri, 31 Aug 2001 16:12:06 +0000
Subject: RE: [PHP] PHP Security
Groups: php.general 
Request: Send a blank email to php-general+get-65512@lists.php.net to get a copy of this message
Thanks for the tip. This is what I am talking about. Even with an error like the one you mention below, preferably the page should die nicely and not output a bunch of secret info or other stuff to the client. I am generally careful to prevent that from happening in all my dealings with my mySQL db by checking all the db connections, results, and things, and killing the execution if there was some error. This works well. But I am sure I have not covered every possibility. I am mainly looking for a list of links or textbooks that outlines some of these things. Johan -----Original Message----- From: Seb Frost [mailto:seb@raceshoot.com] Sent: Friday, August 31, 2001 9:57 AM To: Alfredeen, Johan; php-general@lists.php.net Subject: RE: [PHP] PHP Security Great question - I'd love to know too. I can give you one hint. Make sure that you validate any variables passed in the url. I had a script that should take an integer, and realised if someone put in a fraction or text then the script output errors to the html page showing file and directory names that I wanted hidden. To solve this I used: function SecureInt($var,$default) { if (($var!=0) && ($var*1!=0) && is_int($var*1)) { $var=$var*1; //echo "is int"; } else { $var=$default; //echo "is not int"; } return($var); } $intvar = SecureInt($intvar,1); - seb -----Original Message----- From: Alfredeen, Johan [mailto:johanalfredeen@vp.net] Sent: 31 August 2001 15:54 To: php-general@lists.php.net Subject: [PHP] PHP Security I am looking for a good, practical tutorial on what I should be doing as a developer to create a secure web site (PHP related). I have looked in my PHP text and searched the web, but haven't found anything real useful. I am not interested in Apache or OS security, as this is -hopefully- taken care of by my webhost. So if you know of a good guide, online or off, please contribute. Thanks, Johan PongWorld.com -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net --- Incoming mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.274 / Virus Database: 144 - Release Date: 23/08/2001 --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.274 / Virus Database: 144 - Release Date: 23/08/2001

« previous php.general (#65512) next »