<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PHP Security: Guidelines to Lock Down Your Website</title>
	<atom:link href="http://designreviver.com/tips/php-security-guidelines-to-lock-down-your-website/feed/" rel="self" type="application/rss+xml" />
	<link>http://designreviver.com/tips/php-security-guidelines-to-lock-down-your-website/</link>
	<description></description>
	<lastBuildDate>Sat, 04 Feb 2012 13:48:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Cami</title>
		<link>http://designreviver.com/tips/php-security-guidelines-to-lock-down-your-website/comment-page-1/#comment-21628</link>
		<dc:creator>Cami</dc:creator>
		<pubDate>Sun, 26 Jun 2011 01:29:31 +0000</pubDate>
		<guid isPermaLink="false">http://designreviver.com/?p=1118#comment-21628</guid>
		<description>What a neat article. I had no inkinlg.</description>
		<content:encoded><![CDATA[<div class="KonaBody">What a neat article. I had no inkinlg.</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: web development chennai</title>
		<link>http://designreviver.com/tips/php-security-guidelines-to-lock-down-your-website/comment-page-1/#comment-21018</link>
		<dc:creator>web development chennai</dc:creator>
		<pubDate>Fri, 15 Apr 2011 06:05:15 +0000</pubDate>
		<guid isPermaLink="false">http://designreviver.com/?p=1118#comment-21018</guid>
		<description>Its simply superbtool tips.Nice keep share with me.</description>
		<content:encoded><![CDATA[<div class="KonaBody">Its simply superbtool tips.Nice keep share with me.</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: website development chennai</title>
		<link>http://designreviver.com/tips/php-security-guidelines-to-lock-down-your-website/comment-page-1/#comment-21017</link>
		<dc:creator>website development chennai</dc:creator>
		<pubDate>Fri, 15 Apr 2011 06:02:48 +0000</pubDate>
		<guid isPermaLink="false">http://designreviver.com/?p=1118#comment-21017</guid>
		<description>Its an fantastic PHP tool to secure.And the explanation is superb.I am impressed about this post.wonderful and useful for us.Thanks and keep sharing.</description>
		<content:encoded><![CDATA[<div class="KonaBody">Its an fantastic PHP tool to secure.And the explanation is superb.I am impressed about this post.wonderful and useful for us.Thanks and keep sharing.</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sherwin</title>
		<link>http://designreviver.com/tips/php-security-guidelines-to-lock-down-your-website/comment-page-1/#comment-17674</link>
		<dc:creator>Sherwin</dc:creator>
		<pubDate>Mon, 20 Sep 2010 12:32:58 +0000</pubDate>
		<guid isPermaLink="false">http://designreviver.com/?p=1118#comment-17674</guid>
		<description>Thanks a lot for the great tips. Security is indeed a very important factor to consider for our websites, especially now that there so many hostilities circling in the web.</description>
		<content:encoded><![CDATA[<div class="KonaBody">Thanks a lot for the great tips. Security is indeed a very important factor to consider for our websites, especially now that there so many hostilities circling in the web.</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Miquel</title>
		<link>http://designreviver.com/tips/php-security-guidelines-to-lock-down-your-website/comment-page-1/#comment-11914</link>
		<dc:creator>Miquel</dc:creator>
		<pubDate>Wed, 16 Dec 2009 20:58:39 +0000</pubDate>
		<guid isPermaLink="false">http://designreviver.com/?p=1118#comment-11914</guid>
		<description>I can only echo the misgivings of previous commenters and request that you please remove or amend this article. Whilst the intent behind it is laudable, it proposes unsafe solutions and it is irresponsible of you to continue to present them as such.</description>
		<content:encoded><![CDATA[<div class="KonaBody">I can only echo the misgivings of previous commenters and request that you please remove or amend this article. Whilst the intent behind it is laudable, it proposes unsafe solutions and it is irresponsible of you to continue to present them as such.</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jaspal Singh</title>
		<link>http://designreviver.com/tips/php-security-guidelines-to-lock-down-your-website/comment-page-1/#comment-10922</link>
		<dc:creator>Jaspal Singh</dc:creator>
		<pubDate>Sun, 08 Nov 2009 09:30:18 +0000</pubDate>
		<guid isPermaLink="false">http://designreviver.com/?p=1118#comment-10922</guid>
		<description>Excellent tutorial for PHP Freaks.
Thanks for sharing.</description>
		<content:encoded><![CDATA[<div class="KonaBody">Excellent tutorial for PHP Freaks.<br />
Thanks for sharing.</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Danh ba web 2.0</title>
		<link>http://designreviver.com/tips/php-security-guidelines-to-lock-down-your-website/comment-page-1/#comment-8288</link>
		<dc:creator>Danh ba web 2.0</dc:creator>
		<pubDate>Wed, 08 Jul 2009 11:04:11 +0000</pubDate>
		<guid isPermaLink="false">http://designreviver.com/?p=1118#comment-8288</guid>
		<description>Thanks for great tips, keep up !</description>
		<content:encoded><![CDATA[<div class="KonaBody">Thanks for great tips, keep up !</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: ??????? 02 (29.06 - 05.07.2009) &#124; ?????? ?? ?????? ????????</title>
		<link>http://designreviver.com/tips/php-security-guidelines-to-lock-down-your-website/comment-page-1/#comment-8222</link>
		<dc:creator>??????? 02 (29.06 - 05.07.2009) &#124; ?????? ?? ?????? ????????</dc:creator>
		<pubDate>Mon, 06 Jul 2009 15:37:59 +0000</pubDate>
		<guid isPermaLink="false">http://designreviver.com/?p=1118#comment-8222</guid>
		<description>[...] PHP Security: Guidelines to Lock Down Your Website [...]</description>
		<content:encoded><![CDATA[<div class="KonaBody">[...] PHP Security: Guidelines to Lock Down Your Website [...]</div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eiencafe.com --&#62; New way to graphic</title>
		<link>http://designreviver.com/tips/php-security-guidelines-to-lock-down-your-website/comment-page-1/#comment-8207</link>
		<dc:creator>Eiencafe.com --&#62; New way to graphic</dc:creator>
		<pubDate>Sun, 05 Jul 2009 12:04:06 +0000</pubDate>
		<guid isPermaLink="false">http://designreviver.com/?p=1118#comment-8207</guid>
		<description>&lt;strong&gt;Weekly Fave’s...&lt;/strong&gt;


Another Sunday, another week favorites  .
Week from June 28 to July 4, 2009:
Tutorials
Photoshop  Grunge City  Magic and special light effects need Apophysis, too  Construct a Novel Victorian Theatre Setting  How To Create An Abstract Body Portrait .....</description>
		<content:encoded><![CDATA[<div class="KonaBody"><strong>Weekly Fave’s&#8230;</strong></p>
<p>Another Sunday, another week favorites  .<br />
Week from June 28 to July 4, 2009:<br />
Tutorials<br />
Photoshop  Grunge City  Magic and special light effects need Apophysis, too  Construct a Novel Victorian Theatre Setting  How To Create An Abstract Body Portrait &#8230;..</p></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Boulton</title>
		<link>http://designreviver.com/tips/php-security-guidelines-to-lock-down-your-website/comment-page-1/#comment-8202</link>
		<dc:creator>Chris Boulton</dc:creator>
		<pubDate>Sun, 05 Jul 2009 00:20:03 +0000</pubDate>
		<guid isPermaLink="false">http://designreviver.com/?p=1118#comment-8202</guid>
		<description>There&#039;s two types of sanitization - sanitization for input (saving) and sanitization for output.

addslashes() should NEVER be used to sanitize data for output unless you&#039;re in a Javascript string or similar where you need it slashed. 

htmlspecialchars/html_entities is what you want to do for any data that is being output to HTML, assuming you don&#039;t want anything passed through.

mysql_real_escape_string() (or equivalent for other DB engine you&#039;re using) is what should be used to escape input being supplied around in database queries. Of course, what&#039;s even better are parameterized queries/prepared statements.

The &quot;disable flash&quot; is also awfully inadequate. Not to mention it&#039;s easily bypassed if I do ....

Checking referring pages should also NEVER be relied upon from a security standpoint. Ever. It&#039;s easily forged, can be disabled etc etc. The form keys however, are the correct approach.</description>
		<content:encoded><![CDATA[<div class="KonaBody">There&#8217;s two types of sanitization &#8211; sanitization for input (saving) and sanitization for output.</p>
<p>addslashes() should NEVER be used to sanitize data for output unless you&#8217;re in a Javascript string or similar where you need it slashed. </p>
<p>htmlspecialchars/html_entities is what you want to do for any data that is being output to HTML, assuming you don&#8217;t want anything passed through.</p>
<p>mysql_real_escape_string() (or equivalent for other DB engine you&#8217;re using) is what should be used to escape input being supplied around in database queries. Of course, what&#8217;s even better are parameterized queries/prepared statements.</p>
<p>The &#8220;disable flash&#8221; is also awfully inadequate. Not to mention it&#8217;s easily bypassed if I do &#8230;.</p>
<p>Checking referring pages should also NEVER be relied upon from a security standpoint. Ever. It&#8217;s easily forged, can be disabled etc etc. The form keys however, are the correct approach.</p></div>
]]></content:encoded>
	</item>
</channel>
</rss>

