Security is always a big issue for anyone these days, whether it be for a smaller, simple site or a large, complex corporate site storing personal information and/or credit cards. Thankfully, there are several helpful resources out there to help you, the developer, lock down your site - and this new one from DevShed seeks to do just that.
With all the benefits of e-commerce there are dangers such as identity theft for consumers and cyber attacks on websites. Site owners need take preventative measures. Wellman presents some security procedures and scripts for PHP driven sites.
Life in the digital age certainly has its benefits; I can buy the latest CD, before it even hits the shops, for the cheapest price in the world from a shop thousands of miles away, all without leaving the comfort of my armchair (ok, my office chair). [...] But life in the digital age can also have its downfalls; what if your credit card details are stolen from an online store that you recently made a purchased from? What if your log-in password to a site is hacked and someone takes all of your details, opens up a bank account in your name and takes out a ten grand bank loan?
Though these things aren't likely to happen (thanks to professional security folks), what can you and your site do to prevent malicious attacks (such as Directory Browsing, Reverse Proxying, Source Code Disclosure, and Session Hijacking)? He gives a few sample tactics to get you started, including the use of POST over GET, and storing passwords as hashes instead of in plain text.




