Re: Writing Secure PHP Scripts
| From: | Hellekin O. Wolf | Date: | Tue, 05 Sep 2000 14:44:19 +0000 |
| Subject: | Re: Writing Secure PHP Scripts | ||
| References: | 1 | Groups: | php.qa |
| Request: | Send a blank email to php-qa+get-1222@lists.php.net to get a copy of this message | ||
James Moore wrote:
>
> > Next, I've read several times that "doing this is unsecure" or
> > "that's
> > not safe", but no valid, "safe" example was given...
> >
> > It would be a good policy to help PHP users to learn how to program
> > securely by providing them with tutorials, do's and don't's, FAQs and
> > HOW-TOs...
>
> The safe method is to use the example that will appear in the next manual
> build or simply use HTTP_POST_FILES variables. I am currently trying to
> write a section to the File Uploads feature chapter detailing possible
> security issues, this will also be added to the manual, I will also send a
> note to php-genral about it.
>
> Perhaps a disscussion of a Security Appendix on the PHP Docs list would be a
> good idea.
>
> James
>
*** What do you think of an insert with some icon for security tips,
like the tables used for examples ?
Like :
=============================================================================
[SECURITY]
Using Global Variables with uploaded files can lead to security holes.
Instead, consider using the $HTTP_POST_FILES array
and verify that the file you obtain is really the file that was uploaded
:
[sample *usable* code snippet and not the casual foobar example]
==============================================================================
This kind of approach is used everywhere in technical books and I find
it useful, clear and intuitive.
It would make the manual even more useful and appealing.
Also, it would be easier to maintain PHP Manual's code and why not
introduce specialized subsets of it (code snippets, security tips,
whatever).
hellekin