Re: Writing Secure PHP Scripts

From: Date: Thu, 07 Sep 2000 09:27:39 +0000
Subject: Re: Writing Secure PHP Scripts
References: 1 2 3 4 5 6  Groups: php.qa 
Request: Send a blank email to php-qa+get-1250@lists.php.net to get a copy of this message
I'm using a Security class that allows me to check any user input before proceeding. It currently checks the following : - HTTP_GET_VARS, HTTP_POST_VARS (should be extended to HTTP_*_VARS) - HTTP_REFERER - REMOTE_ADDR (for blacklist) - Existing Session (PHP4 and PHPlib, although that part is quite lame) It uses an array of attack strings (thanks to my friend philippe.langlois@qualys.com for the original method) that is compared against user input. If a pattern matches, the attempt is loggued and eventually the IP is blacklisted. Mail alerts can be sent. Right now the code is very fat and ugly but it's quite efficient AFAIK. Maybe it could be PEARized at some point ? I put it online at : http://hellekin.com/net/php/qa/class.security.phps (Comments in French) note that the default parameters in Security() use Constants defined elsewhere. You should change them before using the class. Feedback most welcome. hellekin

« previous php.qa (#1250) next »