Writing Secure PHP Scripts
| From: | Hellekin O. Wolf | Date: | Tue, 05 Sep 2000 13:15:54 +0000 |
| Subject: | Writing Secure PHP Scripts | ||
| Groups: | php.qa | ||
| Request: | Send a blank email to php-qa+get-1219@lists.php.net to get a copy of this message | ||
Hi,
regarding the current discussion about the "File_Upload Security Hole"
on PHP-DEV
and previous (unswered) questions I had on security on another list
(namely phplib)
I'd like to open a discussion on How To Write Secure PHP Scripts.
Probably most people here have enough programming ewperience not to
trust user input and really filter it correctly, but as security issues
are "moving targets", maybe it would be a good idea to propose an
educational approach to secure PHP programming.
For example I was told that looping to $HTTP_POST_VARS was unsecure but
was unable to obtain extensive information about why it is so.
I'm using such loops as follows :
// First, find any (identified) attack string
// $attack_strings is an array of identified attack patterns (such as
'../../' or '<script')
reset($HTTP_POST_VARS);
while (list($k,$v) = each($HTTP_POST_VARS)) {
// Check validity of input
reset($attack_strings);
if (in_array($v,$attack_strings)) {
// An attack string was detected...
}
}
reset($HTTP_POST_VARS);
// Then loop through $HTTP_POST_VARS to validate user input
an so on. What's wrong with that ?
Next, I've read several times that "doing this is unsecure" or "that's
not safe", but no valid, "safe" example was given...
It would be a good policy to help PHP users to learn how to program
securely by providing them with tutorials, do's and don't's, FAQs and
HOW-TOs...
Programming securely is not a granted thing. It has to be taught and
learnt. Even when learnt, no program is exempt from security risks, as
proven by the ever-flowing BugTraq or security advisories. The thing is
that if developpers know how to avoid security holes that might be
considered basic to most of you, the overall quality would be increased.
Nasty bugs requiring in-depth knowledge of buffer overflows or other
sorcery-like kind of bugs won't be prevented of course, but drawing
attention to security should help.
My 2c.
hellekin