You are here: Re: question about safe « PHP Programming Language « IT news, forums, messages
Re: question about safe

Posted by Rik Wasmus on 09/28/65 12:01

> Uzytkownik "Rik Wasmus" <luiheidsgoeroe@hotmail.com> napisal w =

> wiadomosci news:op.t5lsmesk5bnjuv@metallium.lan...
> On Sun, 27 Jan 2008 20:30:14 +0100, MZ <marcinzmyslowski@poczta.onet.p=
l>
> wrote:
> Hello!
> How to prevent from such try of attack of the website?
> http://www.example.com/index.php?id=3D0?;print_r(glob('*'));echo%20%2=
2
> By just not running/eval()ing arbitrary code from outside? You'd real=
ly
> have to provide the mechanism for the hacker for this to work, it is n=
ot
> an inherent vulnerability of PHP.

On Sun, 27 Jan 2008 20:37:56 +0100, MZ <marcinzmyslowski@poczta.onet.pl>=
=

wrote:
> Sorry English language is not my national language.
> Please explain to me in details this sentence:
>By just not running/eval()ing arbitrary code from outside?
> What do you mean by asking me it?
> You said that is not the weakness of PHP. Do you mean that PHP is
> such attacks proof?
> Thank you and sorry for such question

Yes, PHP will NOT execute code from the URL without you telling it to.
What you DO want to check for is SQL injection (google it).
-- =

Rik Wasmus

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация