Writing Secure PHP Scripts

From: Date: Tue, 05 Sep 2000 13:15:54 +0000
Subject: Writing Secure PHP Scripts
Groups: php.qa 
Request: Send a blank email to php-qa+get-1219@lists.php.net to get a copy of this message
Hi, regarding the current discussion about the "File_Upload Security Hole" on PHP-DEV and previous (unswered) questions I had on security on another list (namely phplib) I'd like to open a discussion on How To Write Secure PHP Scripts. Probably most people here have enough programming ewperience not to trust user input and really filter it correctly, but as security issues are "moving targets", maybe it would be a good idea to propose an educational approach to secure PHP programming. For example I was told that looping to $HTTP_POST_VARS was unsecure but was unable to obtain extensive information about why it is so. I'm using such loops as follows : // First, find any (identified) attack string // $attack_strings is an array of identified attack patterns (such as '../../' or '<script') reset($HTTP_POST_VARS); while (list($k,$v) = each($HTTP_POST_VARS)) { // Check validity of input reset($attack_strings); if (in_array($v,$attack_strings)) { // An attack string was detected... } } reset($HTTP_POST_VARS); // Then loop through $HTTP_POST_VARS to validate user input an so on. What's wrong with that ? Next, I've read several times that "doing this is unsecure" or "that's not safe", but no valid, "safe" example was given... It would be a good policy to help PHP users to learn how to program securely by providing them with tutorials, do's and don't's, FAQs and HOW-TOs... Programming securely is not a granted thing. It has to be taught and learnt. Even when learnt, no program is exempt from security risks, as proven by the ever-flowing BugTraq or security advisories. The thing is that if developpers know how to avoid security holes that might be considered basic to most of you, the overall quality would be increased. Nasty bugs requiring in-depth knowledge of buffer overflows or other sorcery-like kind of bugs won't be prevented of course, but drawing attention to security should help. My 2c. hellekin

« previous php.qa (#1219) next »