October 13, 201114 yr Hello all. I'm a bit of a PHP noob, especially when it comes to security, so I've been lurking around the web looking at a bunch of articles that talk of some do's and dont's when considering making your PHP-driven website secure. Among the many security concerns there are two that call to my attention. Session Hijacking and SQL Insertion. I'm worried about the former because I pass some variables into a session, however, these variables do not contain any critical data, the only contain error messages. Here's a snippet: // Make sure the user selected atleast one item... if(empty($selection)) { $err[] = "ERROR - You did not select anything to delete."; $_SESSION["errors"] = $err; header("Location: img_del.php?doAction=delete&doCheck=failed"); exit(); } // Display Error Messages if($_GET["doCheck"] == "failed") { // Post errors, if any... echo "<p class=\"error\">"; foreach($_SESSION["errors"] as $key=>$e) { echo "* $e <br />"; } echo "</p>"; unset($_SESSION["errors"]); // unset the error variable... } I'm aware of some preventive measures that can be taken to avoid session hijacking, however, should I regenerate the session id even if the data contained in the session is non-critical? Can the snippet above be exploited in any way? As for the latter, SQL Injection, while searching the web for common security techniques I stumbled across a useful function that filters the input data from a form: /* This code filters harmful script code and escapes data of all POST data from the user submitted form. */ function filter($data) { $data = trim(htmlentities(strip_tags($data))); if(get_magic_quotes_gpc()) $data = stripslashes($data); $data = mysql_real_escape_string($data); return $data; } // Loop through input values and filter... foreach($_POST as $key => $value) { $data[$key] = filter($value); } Since the filter function is using mysql_real_escape_string to filter the data when querying the DB, I don't really take any other security measures afterwards. Is it bad practice to assign $data["input"] straight to a variable to be later used when querying the DB? Thanks in advance for any tips given! Edited October 13, 201114 yr by larsson719
October 13, 201114 yr 1 - No, data in the session is set by the server not the client so if its just strings then you don't need to worry about session hijacking. You'd only worry about that kind of stuff if you had a secure area where a hijacker could intercept the session id and access the secure area. If that is the case then there are techniques to regenerate the session, checking things like user agent, IP, country, etc. 2 - I will probably get shot down on here again for suggesting this but unless you know what your doing you shouldn't use the ancient mysql functions like mysql_real_escape_string, you should use PDO and prepared statements as they are immune to SQL injection - http://www.php.net/manual/en/pdostatement.bindvalue.php 3 - Obviously you will still want to filter your data (e.g prevent an invalid email address) for this use the native filter functions - http://php.net/manual/en/book.filter.php Also don't use Magic Quotes. Turn it off on your server, its deprecated as of PHP5.3 - http://php.net/manual/en/security.magicquotes.php
October 13, 201114 yr I think jock has covered all bases , and I must say I tend to opt for the mysql_real_escape_string/mysql_escape_string for most applications (one of us had to say it ) but this really depends on the level of security the application requires but as said each to their own. Somewhat of a commonly overlooked and simple solution that short of cross-site scripting attacks or gaining access to the client PC, is SSL. At around £15/35 a year It is worth the investment and must be noted as it is being used much more widely now. My personal opinion is that SSL should be used on any site that requires a login and or personal/private data, simply because these days anyone, especially in/on public/work/college/university networks can simply monitor the packets and pickup your password, username or data in transit. An example of this that always springs to mind was that of a test carried out at the university I attend, In which a wireless network was enabled in an on campus location by the IT staff and selected students under the BSC Hons for forensic computing. It was enabled for precisely 1 hour and no data was recorded, additionally the computer formatted and data onscreen was filtered (hashed),however within that period if memory serves me near 300 separate username/password combinations as well as 30 full credit/debit card details were seen which is rather shocking. Equality the same could be done via a laptop gaining access to your home wireless at an extreme end of the scale. Like all security fixes and precautions it certainly is another more intimidating obstacle than can be put in the way of possible attacks. Note - You must ensure that cookies are sent only via SSL in if you where to use SSL Edited October 13, 201114 yr by CSN-UK
October 14, 201114 yr Author Thanks for pointing out the PDO extension, jock, I was not aware that this existed but it seems like a more secure alternative. I think jock has covered all bases , and I must say I tend to opt for the mysql_real_escape_string/mysql_escape_string for most applications (one of us had to say it ) but this really depends on the level of security the application requires but as said each to their own. I will look into SSL as I'm planning on setting up a small e-commerce system as well--meaning there will be some sensitive data being sent through the system. Perhaps with SSL, it can make up for any lack of security I may have in the system... although I will try to patch up as many security holes as possible. Edited October 14, 201114 yr by larsson719
Create an account or sign in to comment