Best way to avoid code injection in PHP ??

Discussion in 'PHP' started by nehrav, Nov 19, 2009.

  1. #1
    Hi experts,

    Plz, plz suggest me the best ways to avoid code injections in PHP

    Thanks
     
    nehrav, Nov 19, 2009 IP
  2. hans

    hans Well-Known Member

    Messages:
    2,923
    Likes Received:
    126
    Best Answers:
    1
    Trophy Points:
    173
    #2
    install snort if you have your own server
     
    hans, Nov 19, 2009 IP
  3. nehrav

    nehrav Peon

    Messages:
    46
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #3
    No, I don't have my own server.
    I just want some guidelines that need to keep in mind while coding.

    Thanks
     
    nehrav, Nov 19, 2009 IP
  4. mastermunj

    mastermunj Well-Known Member

    Messages:
    687
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    110
    #4
    one simple rule, sterilize all inputs coming from user ..
     
    mastermunj, Nov 19, 2009 IP
  5. taminder

    taminder Peon

    Messages:
    581
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #5
    I'm sure there are online tools to check your code for vulnerabilities. if it's a really important site or if you get a lot of hackers visiting, I suggest you have your own server from home or colocate with a cheap provider.
     
    taminder, Nov 19, 2009 IP
  6. mastermunj

    mastermunj Well-Known Member

    Messages:
    687
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    110
    #6
    acunetix is the tool i have recently learned about if you are looking for vulnerabilities detector tool.
     
    mastermunj, Nov 19, 2009 IP
  7. xenon2010

    xenon2010 Peon

    Messages:
    237
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #7
    use stripslashes($input) and html_entities($input) functions...
    2 powerful functions..
    and lastly. use str_replace to replace javascript functions just like this:
    str_ireplace('javascript','java<b></b>script',$input);
    this will disable all javascript functions..
    my 3 cents :D
     
    xenon2010, Nov 19, 2009 IP