Re: Writing Secure PHP Scripts
| From: | Hellekin O. Wolf | Date: | Thu, 07 Sep 2000 09:27:39 +0000 |
| Subject: | Re: Writing Secure PHP Scripts | ||
| References: | 1 2 3 4 5 6 | Groups: | php.qa |
| Request: | Send a blank email to php-qa+get-1250@lists.php.net to get a copy of this message | ||
I'm using a Security class that allows me to check any user input before
proceeding.
It currently checks the following :
- HTTP_GET_VARS, HTTP_POST_VARS (should be extended to HTTP_*_VARS)
- HTTP_REFERER
- REMOTE_ADDR (for blacklist)
- Existing Session (PHP4 and PHPlib, although that part is quite lame)
It uses an array of attack strings (thanks to my friend
philippe.langlois@qualys.com for the original method) that is compared
against user input. If a pattern matches, the attempt is loggued and
eventually the IP is blacklisted. Mail alerts can be sent.
Right now the code is very fat and ugly but it's quite efficient AFAIK.
Maybe it could be PEARized at some point ?
I put it online at : http://hellekin.com/net/php/qa/class.security.phps
(Comments in French)
note that the default parameters in Security() use Constants defined
elsewhere.
You should change them before using the class.
Feedback most welcome.
hellekin