Delphi For PHP Forums       


Go Back   Delphi-PHP Forums > Programming > PHP - Security
Forum Jump Register FAQ Members List Downloads Search Today's Posts Mark Forums Read

PHP - Security What's the best way to protect your PHP applications? Questions and answers should be posted here.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 8th September 2009, 15:53
D4PHP User
 
Join Date: Feb 2009
Posts: 12
PxTVmx is on a distinguished road
Default Security questions

I'm about to release my first d4php based site (is also my first web programming project, a very simple website, but for many users - is a school environment-) and have questions about security, would be very grateful if someone could help me:

Is there any way (beyond steal my password) that anyone can download the PHP sources from my site (thus someone could, for example, to access the database login user and password)? if so, what should I do to avoid this risk?

What security measures should be taken before releasing a PHP based website?

Thank you in advance.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 8th September 2009, 20:34
405hp's Avatar
Firebug Fanatic
 
Join Date: Dec 2007
Location: State of Confusion
Posts: 3,272
405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute
Default

afaik the only way someone can see the php code is if the php complier on the server is shutdown. Not sure how it happens but probably only on a setup issue.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 9th September 2009, 17:08
D4PHP User
 
Join Date: Feb 2009
Posts: 12
PxTVmx is on a distinguished road
Default

Thank you very much for your reply, 405hp.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 5th January 2010, 23:57
just Joined!
 
Join Date: Jan 2010
Posts: 2
MrTudorLovingBux is on a distinguished road
Default :gotme:Please help me someone:gotme: :(

Hello!:
I gave some issues...
First issue is:How do you protect youre self from Software that downloads all the files from a website? ( Like Offline Surfers)
Second: I have to create a website. It will be like this: Main form with all other stuff, login-register-reset password form, the usser forms (multiple ones) with logout included. Can you help me secure this website and give me a working good very hard to hack template (with MD5 please)?
Third: I want to use SHA1 insead of MDS Hash, is SHA1 more secure? Edit: or SHA-2
Fourth: I will buy RapidSSL Certificate, how will I integrate it?
Fifth: How I destroy a session when "logout" and how to remember the username and password?

Please help me, I will get back later in the day, I will be at work.

Thank You very much!

Last edited by MrTudorLovingBux; 6th January 2010 at 06:51.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 6th January 2010, 01:20
405hp's Avatar
Firebug Fanatic
 
Join Date: Dec 2007
Location: State of Confusion
Posts: 3,272
405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute
Default

Are you using the Delphi for PHP/VCL or just plain old PHP?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 6th January 2010, 06:46
just Joined!
 
Join Date: Jan 2010
Posts: 2
MrTudorLovingBux is on a distinguished road
Default

I am using Delphi for PHP.
I will be so glad if you could help me...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 6th January 2010, 12:54
405hp's Avatar
Firebug Fanatic
 
Join Date: Dec 2007
Location: State of Confusion
Posts: 3,272
405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute405hp has a reputation beyond repute
Default

authorization login script
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT +1. The time now is 05:58.




Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.0 ©2009, Crawlability, Inc.
Copyright © 2004 - 2009, G&J Solutions Ltd. All Rights Reserved. terms of use