Jump to content

Recommended Posts

Posted

PHP is a very easy language to learn, and many people without any sort of background in programming learn it as a way to add interactivity to their web sites. Unfortunately, that often means PHP programmers, especially those newer to web development, are unaware of the potential security risks their web applications can contain. Here are a few of the more common security problems and how to avoid them.

 

Rule Number One: Never, Ever, Trust Your Users

 

It can never be said enough times, you should never, ever, ever trust your users to send you the data you expect. I have heard many people respond to that with something like "Oh, nobody malicious would be interested in my site". Leaving aside that that could not be more wrong, it is not always a malicious user who can exploit a security hole - problems can just as easily arise because of a user unintentionally doing something wrong.

 

So the cardinal rule of all web development, and I can't stress it enough, is: Never, Ever, Trust Your Users. Assume every single piece of data your site collects from a user contains malicious code. Always. That includes data you think you have checked with client-side validation, for example using JavaScript. If you can manage that, you'll be off to a good start. If PHP security is important to you, this single point is the most important to learn.

 

SQL Injection

 

One of PHP's greatest strengths is the ease with which it can communicate with databases, most notably MySQL. Many people make extensive use of this, and a great many sites, including this one, rely on databases to function.

 

However, as you would expect, with that much power there are potentially huge security problems you can face. Fortunately, there are plenty of solutions. The most common security hazard faced when interacting with a database is that of SQL Injection - when a user uses a security glitch to run SQL queries on your database.

 

Let's use a common example. Many login systems feature a line that looks a lot like this when checking the username and password entered into a form by a user against a database of valid username and password combinations, for example to control access to an administration area:

$check = mysql_query("SELECT Username, Password, UserLevel FROM Users WHERE Username = '".$_POST['username']."' and Password = '".$_POST['password']."'");

Look familiar? It may well do. And on the face of it, the above does not look like it could do much damage. But let's say for a moment that I enter the following into the "username" input box in the form and submit it:

' OR 1=1 #

The query that is going to be executed will now look like this:

SELECT Username, Password FROM Users WHERE Username = '' OR 1=1 #' and Password = ''

The hash symbol (#) tells MySQL that everything following it is a comment and to ignore it. So it will actually only execute the SQL up to that point. As 1 always equals 1, the SQL will return all of the usernames and passwords from the database. And as the first username and password combination in most user login databases is the admin user, the person who simply entered a few symbols in a username box is now logged in as your website administrator, with the same powers they would have if they actually knew the username and password.

 

With a little creativity, the above can be exploited further, allowing a user to create their own login account, read credit card numbers or even wipe a database clean.

 

Fortunately, this type of vulnerability is easy enough to work around. By checking for apostrophes in the items we enter into the database, and removing or neutralising them, we can prevent anyone from running their own SQL code on our database. The function below would do the trick:

function make_safe($variable) { $variable = mysql_real_escape_string(trim($variable)); return $variable; }

Now, to modify our query. Instead of using _POST variables as in the query above, we now run all user data through the make_safe function, resulting in the following code:

$username = make_safe($_POST['username']); $password = make_safe($_POST['password']); $check = mysql_query("SELECT Username, Password, UserLevel FROM Users WHERE Username = '".$username."' and Password = '".$password."'");

Now, if a user entered the malicious data above, the query will look like the following, which is perfectly harmless. The following query will select from a database where the username is equal to "\' OR 1=1 #".

SELECT Username, Password, UserLevel FROM Users WHERE Username = '\' OR 1=1 #' and Password = ''

Now, unless you happen to have a user with a very unusual username and a blank password, your malicious attacker will not be able to do any damage at all. It is important to check all data passed to your database like this, however secure you think it is. HTTP Headers sent from the user can be faked. Their referral address can be faked. Their browsers User Agent string can be faked. Do not trust a single piece of data sent by the user, though, and you will be fine.

 

Using Defaults

 

When MySQL is installed, it uses a default username of "root" and blank password. SQL Server uses "sa" as the default user with a blank password. If someone finds the address of your database server and wants to try to log in, these are the first combinations they will try. If you have not set a different password (and ideally username as well) than the default, then you may well wake up one morning to find your database has been wiped and all your customers' credit card numbers stolen. The same applies to all software you use - if software comes with default username or password, change them.

Leaving Installation Files Online

 

Many PHP programs come with installation files. Many of these are self-deleting once run, and many applications will refuse to run until you delete the installation files. Many however, will not pay the blindest bit of attention if the install files are still online. If they are still online, they may still be usable, and someone may be able to use them to overwrite your entire site.

 

Predictability

 

Let us imagine for a second that your site has attracted the attention of a Bad Person. This Bad Person wants to break in to your administration area, and change all of your product descriptions to "This Product Sucks". I would hazard a guess that their first step will be to go to http://www.yoursite.com/admin/ - just in case it exists. Placing your sensitive files and folders somewhere predictable like that makes life for potential hackers that little bit easier.

 

With this in mind, make sure you name your sensitive files and folders so that they are tough to guess. Placing your admin area at http://www.yoursite.com/jsfh8sfsifuhsi8392/ might make it harder to just type in quickly, but it adds an extra layer of security to your site. Pick something memorable by all means if you need an address you can remember quickly, but don't pick "admin" or "administration" (or your username or password). Pick something unusual.

 

The same applies to usernames and passwords. If you have an admin area, do not use "admin" as the username and "password" as the password. Pick something unusual, ideally with both letters and numbers (some hackers use something called a "dictionary attack", trying every word in a dictionary as a password until they find a word that works - adding a couple of digits to the end of a password renders this type of attack useless). It is also wise to change your password fairly regularly (every month or two).

 

Finally, make sure that your error messages give nothing away. If your admin area gives an error message saying "Unknown Username" when a bad username is entered and "Wrong Password" when the wrong password is entered, a malicious user will know when they've managed to guess a valid username. Using a generic "Login Error" error message for both of the above means that a malicious user will have no idea if it is the username or password he has entered that is wrong.

 

File Systems

 

Most hosting environments are very similar, and rather predictable. Many web developers are also very predictable. It doesn't take a genius to guess that a site's includes (and most dynamic sites use an includes directory for common files) is an www.website.com/includes/. If the site owner has allowed directory listing on the server, anyone can navigate to that folder and browse files.

 

Imagine for a second that you have a database connection script, and you want to connect to the database from every page on your site. You might well place that in your includes folder, and call it something like connect.inc. However, this is very predictable - many people do exactly this. Worst of all, a file with the extension ".inc" is usually rendered as text and output to the browser, rather than processed as a PHP script - meaning if someone were to visit that file in a browser, they'll be given your database login information.

 

Placing important files in predictable places with predictable names is a recipe for disaster. Placing them outside the web root can help to lessen the risk, but is not a foolproof solution. The best way to protect your important files from vulnerabilities is to place them outside the web root, in an unusually-named folder, and to make sure that error reporting is set to off (which should make life difficult for anyone hoping to find out where your important files are kept). You should also make sure directory listing is not allowed, and that all folders have a file named "index.html" in (at least), so that nobody can ever see the contents of a folder.

 

Never, ever, give a file the extension ".inc". If you must have ".inc" in the extension, use the extension ".inc.php", as that will ensure the file is processed by the PHP engine (meaning that anything like a username and password is not sent to the user). Always make sure your includes folder is outside your web root, and not named something obvious. Always make sure you add a blank file named "index.html" to all folders like include or image folders - even if you deny directory listing yourself, you may one day change hosts, or someone else may alter your server configuration - if directory listing is allowed, then your index.html file will make sure the user always receives a blank page rather than the directory listing. As well, always make sure directory listing is denied on your web server (easily done with .htaccess or httpd.conf).

 

I will update guide from time to time with more information as i work in that part of systems engineering, especially php developing.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


  • Posts

    • Gothicc - use my discord name to scam ( .pufa ) all proofs sent to @Celestine and @Dragic
    • I am guessing  that u was trying to open the ActiveAnticheatCrypt file
    • ⚔️ LINEAGE II ETERNAL SIN — ATHENA x45 ⚔️ 🔥 CLASSIC INTERLUDE • L2OFF 🔥 Old-school soul. Modern battlefield. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 🔥 OFFICIAL GRAND OPENING 📅 31 OCTOBER 2026 🕖 19:00 GMT+2 Prepare your character. Gather your clan. The battle for Athena begins. 🌐 WEBSITE https://eternalsinl2.com/ 👤 REGISTER / ACCOUNT PANEL https://eternalsinl2.com/ucp/ ⬇️ DOWNLOAD & CONNECT https://eternalsinl2.com/connect.php 🎁 VOTE & CLAIM REWARD https://eternalsinl2.com/vote/ 💬 DISCORD https://discord.gg/GBwZwxeUWD ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ⚔️ ATHENA x45 — SERVER RATES ⭐ Experience: x45 ⭐ Skill Points: x55 💰 Adena: x200 💎 Spoil: x25 🔴 Seal Stones: x5 🎁 General Drop: x1 ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ✨ ENCHANT SYSTEM 🔸 Safe Enchant: +3 🔸 Maximum Weapon: +20 🔸 Maximum Armor: +8 🔸 Warrior Weapon Enchant Rate: 60% 🔸 Magic Weapon Enchant Rate: 45% A familiar Interlude enchant system with enough progression to keep both farming and PvP meaningful. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 💰 ECONOMY & PROGRESSION Athena x45 features a custom progression economy built around several important currencies and materials: 💎 Ancient Adena 🩸 Blood of Chaos 🔴 Red Seal Stones 🔵 Blue Seal Stones 🟢 Green Seal Stones Seal Stones obtained through Mithril Mines provide one of the main Ancient Adena progression paths. Blood of Chaos is an important material obtained through custom farming and spoil content. It is also used for the S-Grade Special Ability system. 🛒 General shops provide equipment up to B Grade. ⚔️ A-Grade Weapons and Armor are available through the Merchant using Adena + Ancient Adena. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 🛡️ S-GRADE SPECIAL ABILITIES Obtaining S Grade is not the end of your equipment progression. Athena introduces an expanded S-Grade equipment system where S-Grade armor can receive custom Special Abilities. Example: ⚔️ Draconic Leather Armor — Assassin Blood of Chaos plays an important role in unlocking these upgrades. Build your equipment around your character and continue improving it through Athena's endgame progression. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ⚔️ ANCIENT WEAPONS & ENDGAME EQUIPMENT Customized Raid Bosses provide access to additional endgame progression: ⚔️ Ancient Weapons 🛡️ Eternal Equipment 👑 Epic Equipment 💎 Additional progression materials Customized Raid Bosses around Mithril Mines can reward Ancient Weapons and other valuable progression items. Eternal and Epic Armor are connected to Grand Boss endgame progression, with Epic Armor available at a low drop chance. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 🌍 CUSTOM FARMING & PvP ZONES ⛏️ MITHRIL MINES ENTRANCE Recommended Level: 61–74 / 65–75 Farm: 🟢 Green Seal Stones 🔵 Blue Seal Stones Begin your Seal Stone and Ancient Adena progression before moving deeper into the custom farming areas. ━━━━━━━━━━━━━━━━━━ 🔥 IMPERIAL TOMB — CHAOTIC Recommended Level: 72–78 ⚔️ FARM + PvP ZONE Monsters can drop: ⚔️ S-Grade Weapons 🩸 Blood of Chaos Imperial Tomb is one of Athena's primary S-Grade Weapon farming locations. Karma players do not drop their items when killed inside the configured Chaotic rooms. Farm, fight and defend your territory. ━━━━━━━━━━━━━━━━━━ 🌋 FORGE OF THE GODS ⚔️ S-GRADE FARMING ZONE Forge of the Gods provides another progression route for: ⚔️ S-Grade Weapons Unlike Imperial Tomb, Forge of the Gods is not configured as a Chaotic PvP zone. Choose your preferred farming route. ━━━━━━━━━━━━━━━━━━ 💎 MITHRIL MINES CENTER Recommended Level: 74–78 Farm: 🟢 Green Seal Stones 🔵 Blue Seal Stones 🔴 Red Seal Stones 🩸 Blood of Chaos through Spoil A major progression area for players preparing for Athena's endgame content. ━━━━━━━━━━━━━━━━━━ 👹 MITHRIL MINES GROUNDS Recommended Level: 74–78 Continue your Seal Stone progression and challenge customized Level 80 Raid Bosses. Including: ⚔️ Thief Kelbar ⚔️ Anakim ⚔️ Lilith ⚔️ And more... These bosses form part of Athena's Ancient Weapon and endgame progression. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 🎉 DAILY EVENTS 🎃 SQUASH EVENT Daily activity at Primeval Isle. Hunt event targets using the special event weapon and collect Event Medals. 🍉 WATERMELON EVENT Watermelons spawn around the event area and provide additional Event Medals. 🎁 EVENT REWARDS Exchange your Event Medals for rewards including: ✨ Blessed Enchant Weapon Scrolls ✨ Blessed Enchant Armor Scrolls ✨ Subclass Certifications ✨ Additional Event Rewards ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ✨ BUFFER SYSTEM Athena's buffer has been designed without completely replacing traditional support classes. Important support classes remain relevant, including: • Hierophant • Sword Muse • Eva Saint • Spectral Dancer • Shillen Saint • Doomcryer ⚡ EXOUSIA BUFFER Available Prophecies: 🔥 Prophecy of Fire 🌊 Prophecy of Water 💨 Prophecy of Wind ⚡ Chant of Victory Available through the Ancient Adena economy. ✨ 24 Buff Slots ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 🏆 SUBCLASS • NOBLESSE • OLYMPIAD 🔸 Subclass Quest: REQUIRED 🔸 Noblesse Quest: REQUIRED 🔸 Olympiad: Monthly Heroes Athena keeps important Classic Interlude character progression relevant alongside its custom systems. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 💎 VIP SYSTEM — LEVEL 1 TO 7 Athena includes a complete 7-Level VIP progression system. VIP 1 ➜ VIP 2 ➜ VIP 3 ➜ VIP 4 ➜ VIP 5 ➜ VIP 6 ➜ VIP 7 Players progressively build their VIP status using VIP Points. This provides an additional long-term progression path alongside normal character and equipment progression. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 🛒 L2STORE Athena features an integrated L2Store system, providing access to custom store content directly through its dedicated in-game interface. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ⚙️ GENERAL SERVER FEATURES ✔️ Classic Interlude ✔️ L2OFF Server ✔️ 24 Buff Slots ✔️ Auto Learn Skills ✔️ Offline Shop System ✔️ Offline Buff Shop System ✔️ L2Store ✔️ VIP Level 1–7 ✔️ VIP Points Progression ✔️ Custom Farming Zones ✔️ Custom PvP Zones ✔️ Custom Raid Bosses ✔️ S-Grade Special Abilities ✔️ Ancient Weapons ✔️ Eternal / Epic Equipment Progression ✔️ Daily Events ✔️ Long-Term Character Progression ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 🎁 VOTE & CLAIM REWARD SYSTEM Support Eternal Sin on HopZone and receive an exclusive: ✨ 12-HOUR BONUS RUNE ✨ The Rune provides progression bonuses including: 🔥 EXP Bonus 🔥 SP Bonus 💰 Adena Bonus 💎 Spoil Bonus 🔴 Seal Stones Bonus HOW TO CLAIM 1️⃣ Visit the Eternal Sin Vote page 2️⃣ Vote for Athena x45 on HopZone 3️⃣ Login with your Eternal Sin account 4️⃣ Select your character 5️⃣ Press CHECK VOTE & CLAIM REWARD 6️⃣ If your character is currently online, relog to receive the reward The system includes vote/IP protection to prevent multiple rewards from the same eligible vote. 🎁 VOTE & CLAIM YOUR REWARD: https://eternalsinl2.com/vote/ ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 🚀 HOW TO JOIN ATHENA x45 1️⃣ DOWNLOAD Download the Classic Interlude Client. 2️⃣ INSTALL Download and install the Athena Patch. 3️⃣ CREATE ACCOUNT Create your Eternal Sin account through our Account Panel. 4️⃣ ENTER ATHENA Launch the game, login and begin your journey. ⬇️ DOWNLOAD & CONNECT https://eternalsinl2.com/connect.php 👤 CREATE ACCOUNT https://eternalsinl2.com/ucp/ ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ⚔️ THE BATTLE FOR ATHENA BEGINS ⚔️ 🔥 31 OCTOBER 2026 • 19:00 GMT+2 🔥 Build your character. Prepare your clan. Control the farming zones. Challenge the Raid Bosses. Fight for Olympiad. Dominate Athena. 🔥 PREPARE YOUR TEAM NOW 🔥 ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 🌐 WEBSITE https://eternalsinl2.com/ 👤 REGISTER / ACCOUNT PANEL https://eternalsinl2.com/ucp/ ⬇️ DOWNLOAD & CONNECT https://eternalsinl2.com/connect.php 🎁 VOTE & CLAIM 12-HOUR BONUS RUNE https://eternalsinl2.com/vote/ 💬 DISCORD https://discord.gg/GBwZwxeUWD ━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ⚔️ LINEAGE II ETERNAL SIN — ATHENA x45 ⚔️ Old-school soul. Modern battlefield.
  • Topics

×
×
  • Create New...

Important Information

This community uses essential cookies to function properly. Non-essential cookies and third-party services are used only with your consent. Read our Privacy Policy and We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue..