![]() |
Basic PHP-security must knows?
Anyone have a link to, or have in mind a list of the basic PHP must knows when it comes to security? I'm not even sure what 'injections' are but I know they have something to do with forms.
|
Adrian has written a really nice article here:
https://vborg.vbsupport.ru/showthrea...light=Security This keeps vBulletin specifics in mind. You can always check the PHP manual as well: http://www.php.net/manual/en/security.php |
Quote:
A rather simple way of understanding what a SQL injection is: http://xkcd.com/327/ :D Basically it comes down to never trusting the user, meaning having a very strong filter in between anything they can input and what gets sent to the database. |
Hehe, that comic is spot on.
|
Thanks. That clears up the whole how they can break in thing big time.
|
love the comic :D
|
All times are GMT. The time now is 03:36 AM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|