Skip to Content
Programming PHP
book

Programming PHP

by Rasmus Lerdorf, Kevin Tatroe
March 2002
Intermediate to advanced
528 pages
21h 29m
English
O'Reilly Media, Inc.
Content preview from Programming PHP

Security Redux

Because security is such an important issue, we want to reiterate the main points of this chapter:

  • Check every value supplied to your program to ensure that the data you’re getting is the data you expected to get.

  • Always initialize your variables.

  • Set variables_order. Use $_REQUEST and friends.

  • Whenever you construct a filename from a user-supplied component, check the components with basename( ) and realpath( ).

  • Don’t create a file and then change its permissions. Instead, set umask( ) so that the file is created with the correct permissions.

  • Don’t use user-supplied data with eval( ), preg_replace( ) with the /e option, or any of the system commands (exec( ), system( ), popen( ), passthru( ), and the backtick (``) operator).

  • Store code libraries and data outside the document root.

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Programming PHP, 3rd Edition

Programming PHP, 3rd Edition

Rasmus Lerdorf, Kevin Tatroe, Peter MacIntyre
Programming PHP, 2nd Edition

Programming PHP, 2nd Edition

Rasmus Lerdorf, Kevin Tatroe, Peter MacIntyre
Clean Code in PHP

Clean Code in PHP

Carsten Windler, Alexandre Daubois

Publisher Resources

ISBN: 1565926102Supplemental ContentCatalog PageErrata