Building a more secure php framework

Discussion in 'Programming' started by thechangelephant, Jul 31, 2009.

  1. #1
    Sorry, I couldn't resist this. The member, deathshadow created this excellent article on our new Webmaster forum. I thought I'd share it with you. Feel free to sign up if you want more quality pieces (not tripe ;)).

    Full article: building a more secure php framework

    Excerpt (full article is 3687 words)

     
    Last edited: Jul 31, 2009
    thechangelephant, Jul 31, 2009 IP
  2. szalinski

    szalinski Peon

    Messages:
    341
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #2
    amazing advice, if you could make the framework as light as possible i'd look forward to using it over such bloated frameworks as Zend (althought they might have their advantages - or do they?). thanks :)
     
    szalinski, Aug 12, 2009 IP
  3. alons

    alons Peon

    Messages:
    35
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Well its not really possible to do without globals.
    And even if you do use Globals you must tend to secure the data in the start if its from an outside source.

    The main thing is handling input.
    Thats the place where everything starts!
     
    alons, Aug 13, 2009 IP
  4. premiumscripts

    premiumscripts Peon

    Messages:
    1,062
    Likes Received:
    48
    Best Answers:
    0
    Trophy Points:
    0
    #4
    If you want a secure framework, you shouldn't build it yourself :) There's stuff out there like cakephp, codeigniter, yii, and others that have already gone through this process, and they have a big community of users that can easily report security vulnerabilities if they should occur.
     
    premiumscripts, Aug 13, 2009 IP
  5. jamespv85

    jamespv85 Peon

    Messages:
    238
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #5
    CodeIgniter for the win! But even tried and tested frameworks can be very vulnerable if how it is used is done poorly.
     
    jamespv85, Aug 13, 2009 IP
  6. stOK

    stOK Active Member

    Messages:
    114
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    53
    #6
    Everything related to secure PHP programming already described on www.php.net
    The problem is not many ppl read official docs and since that find that stuff amazing :)
     
    stOK, Aug 13, 2009 IP