Welcome to %1$s. Please log in.

 
: Keep The TechnoWorldInc.com Community Clean: Read Guidelines Here.
Techno World Inc - The Best Technical Encyclopedia Online! | Forum | THE TECHNO CLUB [ TECHNOWORLDINC.COM ] | Programming Zone | PHP |  Make More Secure Php Applications

Daniel Franklin

If you are writing a dynamic web site , you must use a database system like mysql .
Mysql is the most popular one . When you wrote a query like this Select * from adsense where col=1;
As you can see there is no ' , then the attacker can write his query and bypass yours .You can lost your private information and your site can be hacked.
To protect your site , use type casting . If your parameter is an integer use intval() function to protect malicious strings from your website.
If your parameter is a string , you must use addslashes() function .

$query="Select * from computers where os='".addslashes($_GET['os'])."'"; mysql_query($query);

$query="Select * from computers where can_execute_php=".intval($_GET['type']);

2-) xss atacks

Xss means cross site scripting .It depends on session & cookie stealing with javascript codes . if the script writes the parameter to the document without filtering , attacker can enter javascript codes and reach the cookie with document.cookie() function in javascript . To be protected you must use htmlspecialchars() function . it filters special html chars .

3-) Php injections

Eval function in php causes php injections and attacker can execute php code.There is no code to get protected .You must select the string well before you use eval() function.Its not good to give a paramater variable for eval function .

Bugra is a coder & Security tester . He reported a lot of well - known vulnerabilities like hotmail -xss and yahoo - xss . Original article can be found at http://www.getvaluable.info/uncategorized/make-more-secure-php-applications/ or you can visit anything you need for http://www.getvaluable.info

Article Source: http://ezinearticles.com/?expert=Bugra_Bayramoglu

Recent Updates

[August 11, 2025, 08:33:44 AM]

[August 11, 2025, 08:33:44 AM]

[August 11, 2025, 08:33:44 AM]

[August 11, 2025, 08:33:44 AM]

[May 13, 2025, 08:34:25 AM]

[May 13, 2025, 08:34:25 AM]

[May 13, 2025, 08:34:25 AM]

[April 12, 2025, 08:24:20 AM]

[April 12, 2025, 08:24:20 AM]

[April 12, 2025, 08:24:20 AM]

[April 12, 2025, 08:24:20 AM]

[March 12, 2025, 09:35:30 AM]

[March 12, 2025, 09:35:30 AM]

Subscriptions

<style>@import url('https://fonts.googleapis.com/css?family=Montserrat:700');@import url('https://fonts.googleapis.com/css?family=Montserrat:400'); .form-preview { display: flex; flex-direction: column; justify-content: center; margin-top: 30px; padding: clamp(17px, 5%, 40px) clamp(17px, 7%, 50px); max-width: none; border-radius: 6px; box-shadow: 0 5px 25px rgba(34, 60, 47, 0.25); } .form-preview, .form-preview *{ box-sizing: border-box; } .form-preview .preview-heading { width: 100%; } .form-preview .preview-heading h5{ margin-top: 0; margin-bottom: 0; } .form-preview .preview-input-field { margin-top: 20px; width: 100%; } .form-preview .preview-input-field input { width: 100%; height: 40px; border-radius: 6px; border: 2px solid #e9e8e8; background-color: #fff; outline: none; } .form-preview .preview-input-field input { color: #000000; font-family: "Montserrat"; font-size: 14px; font-weight: 400; line-height: 20px; text-align: center; } .form-preview .preview-input-field input::placeholder { color: #000000; opacity: 1; } .form-preview .preview-input-field input:-ms-input-placeholder { color: #000000; } .form-preview .preview-input-field input::-ms-input-placeholder { color: #000000; } .form-preview .preview-submit-button { margin-top: 10px; width: 100%; } .form-preview .preview-submit-button button { width: 100%; height: 40px; border: 0; border-radius: 6px; line-height: 0px; } .form-preview .preview-submit-button button:hover { cursor: pointer; } </style><form data-v-3a89cb67="" action="https://api.follow.it/subscription-form/QUJrWmZTYXZTNTJ5UDdYb2NaeVlQMmdRWTNQenUrdHdueldtWTNVOGk4WVJhVm94L280bzRPbFE1bVcwNDZ1UWJ4T0VFb0FETWJ4QjhhNGo3ekhGVXNRVmhkbXNnUDlZVkh6RWdmWWlveVVvWDZwbVNCcmpGZUVjMTBNN09WREN8dW1lOTY5VVhCNUtYZTJRdGRZV3ZSQWpaWVVpdGtqbjdNTC9HT2RlMndiaz0=/8" method="post"><div data-v-3a89cb67="" class="form-preview" style="background-color: rgb(255, 255, 255); border-style: solid; border-width: 1px; border-color: rgb(204, 204, 204); position: relative;"><div data-v-3a89cb67="" class="preview-heading"><h5 data-v-3a89cb67="" style="text-transform: none !important; font-family: Montserrat; font-weight: bold; color: rgb(0, 0, 0); font-size: 16px; text-align: center;">Get Latest Tech Updates For Free!</h5></div> <div data-v-3a89cb67="" class="preview-input-field"><input data-v-3a89cb67="" type="email" name="email" required="required" placeholder="Enter email" spellcheck="false" style="text-transform: none !important; font-family: Montserrat; font-weight: normal; color: rgb(0, 0, 0); font-size: 14px; text-align: center; background-color: rgb(255, 255, 255);"></div> <div data-v-3a89cb67="" class="preview-submit-button"><button data-v-3a89cb67="" type="submit" style="text-transform: none !important; font-family: Montserrat; font-weight: bold; color: rgb(255, 255, 255); font-size: 16px; text-align: center; background-color: rgb(96, 131, 190);">Subscribe</button></div></div></form>

Resources

  

Make More Secure Php Applications

Started by Daniel Franklin, September 26, 2007, 07:49:55 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

  Print     Print       Print