Showing posts with label sql injection. Show all posts
Showing posts with label sql injection. Show all posts

Sunday, 22 September 2019

Web Security Best Practices for PHP



Cyber crime has been on the increase for decades now, hence the need to ensure that your PHP code is totally secure. There are best practices that are recommended for programmers who want to protect their code from malicious attacks. Some of the important tips and tricks are enumerated in this article to ensure that your application is less vulnerable and without performance issues.

#1 Validate Input Data


There is a lot to do while writing PHP code to ensure that your web application is not easily exploited by certain users. Proper data validation will ensure that your application is protected from the activities of hackers and spammers who have illegitimate motives.

Client-side or server-side validation could be used to guard against problems that come with bad input from a user. Data validation with JavaScript which happens on the client-side is a lot faster with fewer traffic calls. The downside is that it is dependent on the browser, and disabling JavaScript will make your application vulnerable.

Server-side validation, on the other hand, is a lot slower due to several traffic calls, but cannot be manipulated by spammers. Have you ever tried to pick a username while creating a new social media account and got a response stating that it is already taken? That is server-side validation at work.

Validating all forms of data regardless of its source using both techniques is key to ensuring that your app works in the best way possible.

#2 Prevent Cross-Site Scripting (XSS)


Cross-site scripting (XSS) occurs when a user injects code into a web page to bypass certain restrictions. The code which is usually in JavaScript eventually runs on the server and can expose sensitive data of other users.

Web application vulnerabilities like XSS makes it possible for code from untrusted sources to be executed in the victim's browser as a result of poor data validation. Filtering all entries and eliminating special character with functions like stripslashes(), htmlspecialchars(), and trim(). Eliminating tags that would make the malicious code valid ensures that users are not redirected to a different server, keeping their private data protected.



#3 Routine PHP Updates


PHP updates come with security fixes which ensures that your web applications are not easily compromised. Endeavor to update all your sites to the latest PHP version to ensure that there are no bugs and other vulnerability issues.

Running older versions of PHP will have you using deprecated functions which are no longer supported, causing your site to malfunction. These functions are interpreted wrongly, thereby opening loopholes for the exploitation of your code by attackers.

There are a couple of tools that can be used to check for deprecation in your code so that you do not have to update the entire code. PHP Analyzer (Phan) and PHP 7 Migration Assistant Report (MAR) are some powerful tools that check your code line by line for compatibility issues.

#4 Eliminate Session Hijacking Risks


While using a web application, core data is collected during the session which should be stored in a secure location. It is usually saved to a file and is not very efficient as hackers can easily access the entire information contained therein.

Although encrypting session data could work but is not entirely efficient. Storing your data on a database is recommended, ensuring that it is totally safe and easily accessible from different machines. The session_set_save_handler() function lets you control the way that the session data is stored.

#5 Limit File Access


PHP projects feature several files that contain important data which are relevant to the web application. The fact that some of these files do not bear the “.php” extension means that they would not be parsed even when called directly.

However, files that contain sensitive application data should be kept in directories that are not accessible to the end-users. These PHP include files should also be saved in ".php" extension to ensure that everything works perfectly.

Conclusion


Developers all over the world are in a race against time to fix security loopholes in their applications to avoid malicious attacks that could victimize end users. There are several other strategies to ensure that your PHP applications are impenetrable even for skilled hackers. Hence, you need to keep developing yourself as hackers are getting better as well.



Author

Author Bio:

Cynthia Young loves taking every opportunity to share her knowledge with others. Along with digital marketing, Cynthia is also passionate about personal growth and wellness. When she isn’t writing, she can be found hiking with her dog, cooking Thai cuisine, and enjoying hi-tech thrillers. She also frequently writes articles on the company The Word Point translation service.




Wednesday, 7 August 2019

What Every PHP Developer Needs to Know About Cyber Security



PHP which stands for Hypertext Preprocessor is a general-purpose programming language. According to W3techs Web Technology Surveys, at least 79% of websites of the web use PHP as the server-side programming language. In fact, it is way past Java, Ruby, and ASP.NET in market position as well.

Although PHP is a top-ranking and favorite programming language, it faces the same security challenges that everything digital faces. From virus programs to ransomware, websites and web applications built using PHP are not immune to cyber security threats.

Moreover, security is not child’s play either. It is complex, constantly changing and requires patience to set up and monitor.

If you are a PHP developer, you know what I am talking about.

The problem with PHP development is that the entry of barrier is literally zero. Anybody with interest in the framework can become a developer.

The newbies who join the PHP developer workforce are unaware of the risks caused by the mistakes that they make. In this article, I have outlined some such mistakes below:

Playing it easy with admin accounts


Any web admin who has been in the field for some time understands the critical nature of admin accounts. They are like the key a bank’s safety locker. Access to the admin account is all that a hacker needs to take down a website, or worse tweak it to their benefit. As a PHP developer, you must ensure complete security of the admin account before anything else. Do not provide admin access to everyone, keep it limited to certain person.

Not getting trained on cyber security


Cyber security is not something that can learnt once and be done with. Every single day hackers are inventing novel ways of breaking into a system and sneaking away with data. If you want to beat the odds of getting hacked, it is necessary that you get trained on cyber security. It is quite necessary to get SSL certificate when you develop any website in PHP language.



For instance, something very basic as configuring a Wildcard SSL Certificate can help to secure multiple sub domains of a website. Although the website might be small in the initial stages, the Wildcard certificate can help when the number of sub domains are scaled up.

Skimping on password protection


From the log in page to the admin’s account, passwords are the gatekeepers that let in authorized users and stop unauthorized users from gaining access. When PHP developers skimp on password security by allowing users to set weak passwords, they are creating a culture where cyber security is not encouraged. This leads to further cyber security incidents.

To make things easy for you and to do my bit in making the web a safer place for all, I have compiled a list of security best practices. Here it goes:

Update PHP regularly


Like every other CMS platform out there, the engineers at PHP also regularly update the platform. The latest version of PHP is 7.2.8. Studies have already proven that older versions of any CMS are susceptible to attacks and prone to being hacked. So, the first step that you can take towards securing your PHP-based website is to update it regularly.

There are tools that are available online that can help you see whether the version you are using has been deprecated or needs updating.

Some of them are:

Avoid Cross-site scripting (XSS)


Cross-site scripting is a security vulnerability which allows hackers to inject server-side scripts into website’s code. The malicious code allows the hacker to steal information that the user submits to the website. The risk is greater in websites like banking, account-based services and so on where the user’s credentials, account information, etc. could be of monetary value.

The safest bet you can take to prevent XSS is using filters for user input. In other words, you must sanitize every user input before passing it to the website’s server for processing. This would avoid any malicious code from getting into your system.

SQL injection attacks


As the name suggests SQL injection works by injecting malicious SQL codes into a code repository. This would enable the hacker to make a data-driven program to collapse or work in a manner as they desire. For instance, SQL injection attacks are often used to make PHP-based web applications reveal sensitive data like account details of an ecommerce store, personal information of users and so on. To avoid SQL attacks, you should Prepared Statements instead of dynamic SQL queries. Moreover, use of stored procedures that will add extra layer to database.

Hide files from browser


Your PHP web application would have several files that are required to make it run smoothly. These files are often stored on the backend of the application. There are specific frameworks for storing these files, which is not properly selected or configured would let the hackers find their way in to access the files. As a thumb rule, do not store the files in the root directory, instead but in a public folder where they are not easily accessible.

In a nutshell


Becoming a PHP developer brings with it several benefits. But all PHP developers must understand that it takes a whole lot of effort to keep data safe. The groundwork for this must be laid during the development phase itself when security and access controls can be configured proactively.