Affiliate Marketing
Forum Search

Reply
 
LinkBack Thread Tools Display Modes

  #1 (permalink)  
Old 30-08-07
scifind's Avatar
thin[box]king
 
Join Date: Aug 2003
Location: Cambridge
Posts: 1,846
Thanks: 8
Thanked 4 Times in 4 Posts
scifind is an unknown quantity at this point
  HTML Form Security

I am having a piece of software developed by a third party.
PHP mySQL

I don't have to want to validate the code personally. In this code there are forms for data entry, I was wondering if someone knows of some common exploit code / methods that I can use to check the security of this code.
Or, indeed, point me in the direction of a good article on the subject
__________________
Earn an average of £45 per sale. | New Star Trek Trailer | Looking for Mobile Phone Link Swaps
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 30-08-07
Adeel's Avatar
eCommerce Consultant
 
Join Date: Jan 2007
Location: Manchester
Posts: 250
Thanks: 1
Thanked 3 Times in 2 Posts
Adeel is an unknown quantity at this point
  Re: HTML Form Security

You need SSL to secure the pages. see verisign, thawte or Geotrust websites.

if you are asking about normal validation of the forms then use javascript to make sure users fill in required information such as @ sign in email address fields etc

hope it makes sense!

Ciao..
__________________
Adeel Farooq - Guide 4 Shopping UK - email me
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 30-08-07
Registered User
 
Join Date: Dec 2004
Location: Batley, West Yorks
Posts: 12
Thanks: 0
Thanked 0 Times in 0 Posts
simhd is an unknown quantity at this point
  Re: HTML Form Security

This is a good PHP / Mysql security article:

Writing Secure PHP - PHP - ILoveJackDaniels.com

which shows the common exploits for PHP / Mysql sites.

Simon
__________________
Up to 12% commission on aromatherapy, incense, bath, gifts, massage + more.

£10 CASH BONUS on 1st £150 of sales.

http://www.reallyrelaxing.co.uk/affiliate_scheme.php
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 30-08-07
scifind's Avatar
thin[box]king
 
Join Date: Aug 2003
Location: Cambridge
Posts: 1,846
Thanks: 8
Thanked 4 Times in 4 Posts
scifind is an unknown quantity at this point
  Re: HTML Form Security

Quote:
Originally Posted by Adeel View Post
You need SSL to secure the pages. see verisign, thawte or Geotrust websites.

if you are asking about normal validation of the forms then use javascript to make sure users fill in required information such as @ sign in email address fields etc

hope it makes sense!

Ciao..
Hi
Have the js validation already. Not looking to transmit 'secure data' like CC details - but looking at not having php exploit attempts / sql injection hacks etc

simhd
Cheers for the article - looks ideal
__________________
Earn an average of £45 per sale. | New Star Trek Trailer | Looking for Mobile Phone Link Swaps
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #5 (permalink)  
Old 30-08-07
Registered User
 
Join Date: Feb 2006
Location: Gillingham
Posts: 503
Thanks: 0
Thanked 0 Times in 0 Posts
Donk is an unknown quantity at this point
  Re: HTML Form Security

This wikipedia article about SQL injection should give you some hints

SQL injection - Wikipedia, the free encyclopedia

There are quite a few related links at the bottom of the page.

Php.net also has a page about sql injection
If there is a contacts form you should also check there are safeguards to prevent the injection of bcc to create spam emails .
__________________
They came for my 404 and I said nothing
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
New Http/AJAX form for Leadbay Mortgages johnd Finance Vertical Forum 0 04-05-07 02:11 PM
Online Form Security - What Characters Shall I Ban accelerator Widgets, Coding, AJAX, PHP - Technology & Affiliate Marketing 4 23-04-07 06:58 PM
Form spam problem mibut Widgets, Coding, AJAX, PHP - Technology & Affiliate Marketing 16 07-02-07 02:22 AM
HTML Editor for Form Text Area scifind Widgets, Coding, AJAX, PHP - Technology & Affiliate Marketing 3 05-06-06 11:32 AM


Affiliate Marketing RSS Feeds - Contact Us - Affiliate Marketing - Archive - Privacy Statement - Top

Content Relevant URLs by vBSEO 3.2.0 RC7