Previous Thread
Next Thread
Print Thread
Rate Thread
Joined: Mar 2000
Posts: 3,594
Moderator / Template Diva
Moderator / Template Diva
Offline
Joined: Mar 2000
Posts: 3,594
Thanks for the advice, MJ. I left that globals thing turned off on my test board, so everything is being developed with that concern in mind.

But now I've got another question: if I can't use form data as variables, how do I use it??? No tutorial or info I've ever came across says anything other than variables. And that sure seems to be the most efficient way, even if there are some security concerns. But is there some other safer way to use the form data that I should be using? How do other scripts handle it? Like, discussion boards rely on forms quite a bit, so how come we don't see everyone's vB getting hijacked by l33t 5cr1p7 k1dd13z every five minutes?

If it matters, all of my forms use POST instead of GET, which I would think would be safer because the URL query string isn't involved. And for the few things I do use the URL for (mostly telling the script which function to run, same deal as ?ubb=get_topic or what have you), I wrote myself a cute little encryptor thingy that masks the query string before sending it to the browser. It's no RC6, by any means, but it gets the job done and will tack on a few extra minutes before the would-be attacker can figure out how it works and exploit it. The other thing I've got going for me is that almost all of the forms are only in the admin cp area, which is (or will be) protected by user authentication - in theory only company employees will ever even see it, and they're not exactly the most computer-literate group of people I've came across, so I doubt there will be any hostile takeover attempts from them.

Sorry for all the questions, but like I said, I'm very new at this. And my company is very paranoid about security stuff, so I figure I may as well cover all my bases and make this thing as secure as possible. Thanks again. smile

---Jamin


Don't put that signature in your mouth! You don't know where it's been!
Sponsored Links
Entire Thread
Subject Posted By Posted
HTTP header vars not working in PHP Jamin 06/07/2002 9:06 PM
Re: HTTP header vars not working in PHP Brett 06/13/2002 11:26 PM
Re: HTTP header vars not working in PHP Jamin 06/15/2002 12:20 AM
Re: HTTP header vars not working in PHP Brett 06/17/2002 11:58 PM
Re: HTTP header vars not working in PHP Matt Jacob 06/18/2002 11:40 AM
Re: HTTP header vars not working in PHP Jamin 06/21/2002 4:34 PM
Re: HTTP header vars not working in PHP AllenAyres 06/27/2002 9:47 PM
Re: HTTP header vars not working in PHP Matt Jacob 07/03/2002 9:10 AM

Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
Bill B
Bill B
Issaquah, WA
Posts: 87
Joined: December 2001
Forum Statistics
Forums63
Topics37,575
Posts293,931
Members13,824
Most Online6,139
Sep 21st, 2024
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,834
Greg Hard 4,625
Top Posters(30 Days)
Gizmo 1
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2025 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.1
(Snapshot build 20240918)