PHP FAQs and Stickies
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me

The Shed is going Social! Join us on FaceBook and Twitter and chime in on the conversation.

Go Back   Dev Shed ForumsProgramming LanguagesPHP DevelopmentPHP FAQs and Stickies

Closed Thread
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rating: Thread Rating: 28 votes, 4.54 average. Display Modes
 
Unread Dev Shed Forums Sponsor:
  #256  
Old September 29th, 2008, 01:40 AM
jrrsamul jrrsamul is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 2008
Posts: 3 jrrsamul User rank is Sergeant (500 - 2000 Reputation Level)jrrsamul User rank is Sergeant (500 - 2000 Reputation Level)jrrsamul User rank is Sergeant (500 - 2000 Reputation Level)jrrsamul User rank is Sergeant (500 - 2000 Reputation Level)jrrsamul User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 h 2 m 9 sec
Reputation Power: 0
Arrow Greate about PHP, want more about PHP-Nuke Development

The guide lines you have written about PHP security notes is really excellent and very much useful for the me.......


can you share more knowledge about PHP-nuke development?


Reply With Quote
  #257  
Old January 24th, 2009, 07:20 PM
Thr3ddy Thr3ddy is offline
Contributing User
Dev Shed Beginner (1000 - 1499 posts)
 
Join Date: Jan 2004
Posts: 1,014 Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)  Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3
Time spent in forums: 2 Weeks 1 Day 22 h 30 m 57 sec
Reputation Power: 787
Don't know if it's been mentioned but how to keep prying eyes out of your include files:
PHP Code:
Original - PHP Code
  1. if(strpos($_SERVER['SCRIPT_NAME'], __FILE__))
  2. {
  3.     header('Location: ./'); // change to whatever you want
  4. }

$_SERVER['SCRIPT_NAME'] = the currently executing script
__FILE__ = the actual file that's currently being parsed

Reply With Quote
  #258  
Old January 24th, 2009, 07:34 PM
requinix's Avatar
requinix requinix is offline
Still alive
Click here for more information.
 
Join Date: Mar 2007
Location: Washington, USA
Posts: 12,698 requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)  Folding Points: 417516 Folding Title: Super Ultimate Folder - Level 1Folding Points: 417516 Folding Title: Super Ultimate Folder - Level 1Folding Points: 417516 Folding Title: Super Ultimate Folder - Level 1Folding Points: 417516 Folding Title: Super Ultimate Folder - Level 1Folding Points: 417516 Folding Title: Super Ultimate Folder - Level 1Folding Points: 417516 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 5 Months 1 Week 4 Days 4 h 54 m 57 sec
Reputation Power: 8969
Send a message via AIM to requinix Send a message via MSN to requinix Send a message via Yahoo to requinix Send a message via Google Talk to requinix
I've always preferred making the server handle issues like that.

Like an .htaccess with
Code:
Order Allow, Deny
Deny from All

Personally I put my "secret" files in folders named _include or _classes. Starts with an underscore. Then I can use
Code:
RewriteRule (^|/)_ - [R=404]

They try to access a file or directory, they see a 404 message.

Reply With Quote
  #259  
Old January 24th, 2009, 07:39 PM
Thr3ddy Thr3ddy is offline
Contributing User
Dev Shed Beginner (1000 - 1499 posts)
 
Join Date: Jan 2004
Posts: 1,014 Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)Thr3ddy User rank is Major General (70000 - 90000 Reputation Level)  Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3Folding Points: 1045369 Folding Title: Super Ultimate Folder - Level 3
Time spent in forums: 2 Weeks 1 Day 22 h 30 m 57 sec
Reputation Power: 787
I agree but when working on redistributable software (specifically software that is installable by regular users), this is not always an option. If anything the includes, classes and administrative folders should be stored far outside of the http folder.

Reply With Quote
  #260  
Old August 14th, 2009, 09:59 PM
Hammer65's Avatar
Hammer65 Hammer65 is offline
Web Developer/Musician
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Nov 2004
Location: Tennessee Mountains
Posts: 2,315 Hammer65 User rank is General (90000 - 100000 Reputation Level)Hammer65 User rank is General (90000 - 100000 Reputation Level)Hammer65 User rank is General (90000 - 100000 Reputation Level)Hammer65 User rank is General (90000 - 100000 Reputation Level)Hammer65 User rank is General (90000 - 100000 Reputation Level)Hammer65 User rank is General (90000 - 100000 Reputation Level)Hammer65 User rank is General (90000 - 100000 Reputation Level)Hammer65 User rank is General (90000 - 100000 Reputation Level)Hammer65 User rank is General (90000 - 100000 Reputation Level)Hammer65 User rank is General (90000 - 100000 Reputation Level)Hammer65 User rank is General (90000 - 100000 Reputation Level)Hammer65 User rank is General (90000 - 100000 Reputation Level)Hammer65 User rank is General (90000 - 100000 Reputation Level)Hammer65 User rank is General (90000 - 100000 Reputation Level)Hammer65 User rank is General (90000 - 100000 Reputation Level)Hammer65 User rank is General (90000 - 100000 Reputation Level) 
Time spent in forums: 3 Weeks 4 Days 5 h 54 m 16 sec
Reputation Power: 942
Send a message via AIM to Hammer65
If you are running a hosting server, and are having difficulty finding a script that is sending spam, the instructions here will be very useful. The instructions are specific to cPanel, but the concept will work regardless.

It involves a proxy script, between the mail function and the MTA (mail transfer agent) that records mail details and the scripts that sent mail to a log file. The script in the example is a perl script, but it could just as easily be a PHP script.

Incidentally, PHP 5.3 does this natively, but not everyone has it, in fact cPanel software won't support it for a few months.
__________________
Visit my blog PHP && Life for technical articles and technology musings.

Reply With Quote
  #261  
Old January 14th, 2010, 06:20 AM
hostech hostech is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2010
Posts: 4 hostech User rank is Private First Class (20 - 50 Reputation Level)hostech User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 1 h 10 m 41 sec
Reputation Power: 0
Make a secure PHP script

Security tips for PHP


By default, PHP is set to announce its presence whenever anyone asks - this is usually through the web server.
You can turn this off using ServerTokens and ServerSignature. For example, if you leave ServerTokens and ServerSignature on, you can still hide PHP's existence by changing "expose_php" to "Off" in php.ini - this leaves most server information showing, but hides the PHP data.

If you do this, as well as using a different file extension, your use of PHP is mostly hidden. However, if your code generates any error messages, your use of PHP will become immediately obvious. To get around this, and thereby truly hiding PHP, you should force PHP not to display error messages - edit your php.ini file and set "display_errors" to "Off". This will make debugging a little harder, but be sure to set "log_errors" to "On" - this will make sure that whenever your script generates an error, it will be stored away in the error log file so that you can analyse the problem at your leisure.

Reply With Quote
Closed Thread

Viewing: Dev Shed ForumsProgramming LanguagesPHP DevelopmentPHP FAQs and Stickies > [Everyone] Must read Security Notes

Developer Shed Advertisers and Affiliates



Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 


Powered by: vBulletin Version 3.0.5
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

© 2003-2013 by Developer Shed. All rights reserved. DS Cluster - Follow our Sitemap