On PHPBuilder.com today, there's this new column from Ian Gilfillan seeking to help you program your PHP with a focus on security.
Ian Gilfillan's latest article shows us how to keep our PHP programming secure using software updates, register_globals, include files, magic quotes, validation and more!
He talks about several things (as mentioned above) including: Ensuring your software is up to date, Register Globals settings, Include files and the web tree, Avoiding SQL injection attacks with Magic Quotes or addslashes(), Validation (a biggie that's too often forgotten), Outputting HTML, Error reporting, Running Shell commands, File Uploads, and working with Remote files. On some of them, he just touches on the subject, not really diving too deeply into some of the real issues that could come of it.
I'd like to see a series of articles using this column as a framework, providing a more comprehensive look at the vast majority of security issues all in one place...




