RE: [PHP-QA] Writing Secure PHP Scripts
| From: | James Moore | Date: | Tue, 05 Sep 2000 14:30:53 +0000 |
| Subject: | RE: [PHP-QA] Writing Secure PHP Scripts | ||
| References: | 1 | Groups: | php.qa |
| Request: | Send a blank email to php-qa+get-1220@lists.php.net to get a copy of this message | ||
> Next, I've read several times that "doing this is unsecure" or "that's
> not safe", but no valid, "safe" example was given...
>
> It would be a good policy to help PHP users to learn how to program
> securely by providing them with tutorials, do's and don't's, FAQs and
> HOW-TOs...
The safe method is to use the example that will appear in the next manual
build or simply use HTTP_POST_FILES variables. I am currently trying to
write a section to the File Uploads feature chapter detailing possible
security issues, this will also be added to the manual, I will also send a
note to php-genral about it.
Perhaps a disscussion of a Security Appendix on the PHP Docs list would be a
good idea.
James