note 82371 added to security.general
| From: | alex at osu1 dot php dot net | Date: | Tue, 08 Apr 2008 15:53:46 +0000 |
| Subject: | note 82371 added to security.general | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-138024@lists.php.net to get a copy of this message | ||
well, if you're a skilled php programmer, you can avoid many of these dangers..
for example xss... as its the most common attack, filter all the input you gain from the user (not
only with htmlspecialchars but also with more personalized string-checks for specific words and
chars like document.location and so on).
or file injection (filter out ../ and so on).
i admit that php has its weakpoints (sessions...), but nothing is 100% secure (but you can use ssl
for high security projects..)
----
Server IP: 69.147.83.197
Probable Submitter: 195.43.172.90
----
Manual Page -- http://www.php.net/manual/en/security.general.php
Edit -- https://master.php.net/note/edit/82371
Del: integrated -- https://master.php.net/note/delete/82371/integrated
Del: useless -- https://master.php.net/note/delete/82371/useless
Del: bad code -- https://master.php.net/note/delete/82371/bad+code
Del: spam -- https://master.php.net/note/delete/82371/spam
Del: non-english -- https://master.php.net/note/delete/82371/non-english
Del: in docs -- https://master.php.net/note/delete/82371/in+docs
Del: other reasons-- https://master.php.net/note/delete/82371
Reject -- https://master.php.net/note/reject/82371
Search -- https://master.php.net/manage/user-notes.php