The Arcive of vBulletin Modifications Site. |
|
|
#1
|
|||
|
|||
|
Anyone have a link to, or have in mind a list of the basic PHP must knows when it comes to security? I'm not even sure what 'injections' are but I know they have something to do with forms.
|
|
#2
|
|||
|
|||
|
Adrian has written a really nice article here:
https://vborg.vbsupport.ru/showthrea...light=Security This keeps vBulletin specifics in mind. You can always check the PHP manual as well: http://www.php.net/manual/en/security.php |
|
#3
|
||||
|
||||
|
Quote:
A rather simple way of understanding what a SQL injection is: http://xkcd.com/327/ ![]() Basically it comes down to never trusting the user, meaning having a very strong filter in between anything they can input and what gets sent to the database. |
|
#4
|
|||
|
|||
|
Hehe, that comic is spot on.
|
|
#5
|
|||
|
|||
|
Thanks. That clears up the whole how they can break in thing big time.
|
|
#6
|
||||
|
||||
|
love the comic
|
![]() |
|
|
| X vBulletin 3.8.12 by vBS Debug Information | |
|---|---|
|
|
More Information |
|
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|