June 2, 200917 yr I'm currently in the thought process of making a cms for myself so i can manage my own site with it and no one elses as ill intergrate it directly into my site, maybe if i think its good enough use it for other sites, but before that needs to be tested on my site. Few questions: what is safer mysql or file for passwords? My friend who is pretty experianced on coding has suggested file is better becuase it isn't vunurable to mysql injections. but i just aint sure? Can i block directories from normal users seeing them say /forum/ users can see but /downloads/ users can access, i know i can password directories but when access a download for a user so they are limited to one download how would i get passed the password protection, i've read about something to do with this in .htaccess. More too come most probably but thats all for now, You may ask why im making a cms for myself and not using one allready availible, mainly because i want to learn more php and this i think is a good way to learn about a wide range of sources availible to me, and to learn the code more in depth. Many Thanks Ben
June 2, 200917 yr Hi im far from a experienced with mysql but i believe they added a inject code to stop the or 1 from being used.. i found this here http://www.tizag.com/mysqlTutorial/mysql-p...l-injection.php Hope that helps :-)
June 2, 200917 yr Author Hi im far from a experienced with mysql but i believe they added a inject code to stop the or 1 from being used.. i found this here http://www.tizag.com/mysqlTutorial/mysql-p...l-injection.php Hope that helps :-) Thank you for this, it was a very good read and all things that i use or make myself ill check it has this nice little feature. Thank you
June 2, 200917 yr Welcome , I built a mysql small project and was gutted when someone showed me how to extract all users from my database.. I think in my option its better to be in a database than in note files .. But as i said im no pro!
June 2, 200917 yr As long as you provide significant security features on the database, you should be fine. As a rough guide, you should ensure the following are met when interacting with a MySQL database. 1. Ensure that your script is using a limited MySQL account. It should not be able to delete or alter tables in any way and should only be able to delete records if your application requires it. You can setup new MySQL users from the "users" tab in PhpMyAdmin. 2. Ensure that your passwords are encoded using either MD5 or SHA1. You shouldn't be storing plain text passwords. 3. As previously mentioned, always ensure that your SQL queries are escaped to avoid SQL injection attacks. Follow those as a rough guide and you should be fine. Just bear in mind that no matter how secure an application is made to be, someone will always be able to hack it. Just take as many precautions as reasonably possible and keep security in mind when building your app. Dan
June 2, 200917 yr Author Welcome , I built a mysql small project and was gutted when someone showed me how to extract all users from my database.. I think in my option its better to be in a database than in note files .. But as i said im no pro! Man that must of been a shock to you, but at least it taught you how to protect yourself And thats what im trying to find out, caus eif i can stop a directory from being accessed, cause if i can, ill try both methods and see what i prefer, most probably go with mysql cause be easier to maintain with multiple users.
June 2, 200917 yr Author As long as you provide significant security features on the database, you should be fine. As a rough guide, you should ensure the following are met when interacting with a MySQL database. 1. Ensure that your script is using a limited MySQL account. It should not be able to delete or alter tables in any way and should only be able to delete records if your application requires it. You can setup new MySQL users from the "users" tab in PhpMyAdmin. 2. Ensure that your passwords are encoded using either MD5 or SHA1. You shouldn't be storing plain text passwords. 3. As previously mentioned, always ensure that your SQL queries are escaped to avoid SQL injection attacks. Follow those as a rough guide and you should be fine. Just bear in mind that no matter how secure an application is made to be, someone will always be able to hack it. Just take as many precautions as reasonably possible and keep security in mind when building your app. Dan Thanks for the info Dan, will be sure to take as many precautions as i can, ive decided to go with mysql.
June 3, 200917 yr So I can link the autoplant drawing titleblocks to the datbase just fine. But how do I link the non-autoplant but still in the project to a database. I know you can use the DBCONNECT from autocad but I have yet to make that work. Anyone? _______ === XRumer 5.0 Palladium RULEZ! ===
Create an account or sign in to comment