Chapter 11. Security
Terms You’ll Need to Understand
Data filtering
register_globals
SQL injection
Command injection
Cross-site scripting (XSS)
Shared hosting
safe_mode
open_basedir
Techniques You’ll Need to Master
Validating client data
Understanding the
register_globals
directiveEscaping data used in SQL statements
Escaping data used in shell commands
Preventing cross-site scripting attacks
Understanding the
safe_mode
directiveUnderstanding the
open_basedir
directive
Data Filtering
Data filtering, the process of validating data and filtering out that which is invalid, is arguably the cornerstone of Web application security. The basic premise is quite simple: Never trust foreign data, especially data from the client.
There are two fundamentally different approaches ...
Get Zend PHP Certification Study Guide now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.