Table of Contents
1. SQL injection" >1. SQL injection
2. XSS" >2. XSS
3. CSRF" >3. CSRF
$hashedPassword = password_hash('password', PASSWORD_DEFAULT);password_verify('the wrong password', $hashedPassword); // falsepassword_verify('my super cool password', $hashedPassword); // true
Copy after login
Copy after login
" >
$hashedPassword = password_hash('password', PASSWORD_DEFAULT);password_verify('the wrong password', $hashedPassword); // falsepassword_verify('my super cool password', $hashedPassword); // true
Copy after login
Copy after login
/**防御:1. 限制次数2. 验证码3. 防火墙分析 类似 fail2ban*/
Copy after login
Copy after login
" >
/**防御:1. 限制次数2. 验证码3. 防火墙分析 类似 fail2ban*/
Copy after login
Copy after login
vi /etc/ssh/sshd_configfirewall-cmd --list-allfirewall-cmd --add-port=8888/tcp --permanentfirewall-cmd --reload# 如果是阿里云服务器,不要忘记修改阿里云安全组
Copy after login
Copy after login
" >
vi /etc/ssh/sshd_configfirewall-cmd --list-allfirewall-cmd --add-port=8888/tcp --permanentfirewall-cmd --reload# 如果是阿里云服务器,不要忘记修改阿里云安全组
Copy after login
Copy after login
# 修改 mysql 数据库中的 user 表,然后 flush privileges
Copy after login
Copy after login
" >
# 修改 mysql 数据库中的 user 表,然后 flush privileges
Copy after login
Copy after login
vi /etc/ssh/sshd_configPermitRootLogin
Copy after login
Copy after login
" >
vi /etc/ssh/sshd_configPermitRootLogin
Copy after login
Copy after login
5. 上传文件" >5. 上传文件
6. zip *" >6. zip *
7. session 劫持" >7. session 劫持
8. 密码存储" >8. 密码存储
9. 暴力破解" >9. 暴力破解
服务器安全" >服务器安全
1. 修改 22 端口" >1. 修改 22 端口
2. 修改 mysql root 名称" >2. 修改 mysql root 名称
3. 禁止 root 远程登陆" >3. 禁止 root 远程登陆
Home Backend Development PHP Tutorial Detailed explanation of PHP security examples

Detailed explanation of PHP security examples

Mar 06, 2018 am 10:27 AM
php Example Detailed explanation

1. SQL injection

#By inserting SQL commands into Web form submissions or entering query strings for domain names or page requests, it ultimately deceives the server into executing Malicious SQL commands.

Defense: First filter, then perform parameter binding.

2. XSS

Cross Site Scripting

Principle: Embed scripts into web pages in different ways to achieve attack purposes.

Defense: Filter input.

$id = (int) $_REQUEST['id'];if( $id > 0 ){}
Copy after login
Copy after login
$name = htmlentities($_REQUEST['name'], ENT_QUOTES, "UTF-8");// 注意,如果这里不进行转化也是可以的,// 只要在输出的时候进行转化(建立在已经参数绑定的情况下)。
Copy after login
Copy after login

3. CSRF

##Cross-site request forgery Cross-site request forgery

Principle: Helen logged into Weibo and then browsed a harmful site. A fake post on Weibo was forged on the harmful site. At this time, Helen posted a Weibo without knowing it.

Defense: Embed a random token in the Weibo page, and the Weibo server verifies the token value.

4. Clickjacking

ClickJacking

##Principle: Approximately There are two ways. One is that the attacker uses a transparent iframe, covering it on a web page, and then induces the user to operate on the page. At this time, the user will click on the transparent iframe page without knowing it; the other is The attacker uses an image to cover the web page, blocking the original location of the web page.

Defense: Use js to determine whether the frame is under the same domain name. Add header directive: X-Frame-Options.

// js if (top.location.hostname !== self.location.hostname) {    alert("您正在访问不安全的页面,即将跳转到安全页面!");    top.location.href = self.location.href;}// Apache 配置:Header always append X-Frame-Options SAMEORIGIN// nginx 配置:add_header X-Frame-Options SAMEORIGIN;
Copy after login
Copy after login
5. Upload files

Principle: Various types of illegal software may be uploaded.

Defense: detection type, detection size.

6. zip *

Principle: Some zip files look very small but are very large after decompression

Defense: Do not do this: decompress, process, and then compress compressed files uploaded by users. Because when you decompress, your server is likely to be crowded.

7. Session hijacking

Principle: When the client and server communicate, the hacker captures the packet and obtains the sessionid , and eventually the hacker communicates with the server.

Defense:

Set HttpOnly and reset sessionid from time to time.

8. Password storage

$hashedPassword = password_hash('password', PASSWORD_DEFAULT);password_verify('the wrong password', $hashedPassword); // falsepassword_verify('my super cool password', $hashedPassword); // true
Copy after login
Copy after login

9. Brute force cracking

/**防御:1. 限制次数2. 验证码3. 防火墙分析 类似 fail2ban*/
Copy after login
Copy after login

server Security

1. Modify port 22

vi /etc/ssh/sshd_configfirewall-cmd --list-allfirewall-cmd --add-port=8888/tcp --permanentfirewall-cmd --reload# 如果是阿里云服务器,不要忘记修改阿里云安全组
Copy after login
Copy after login

2. Modify mysql root name

# 修改 mysql 数据库中的 user 表,然后 flush privileges
Copy after login
Copy after login

3. Prohibit root remote login

vi /etc/ssh/sshd_configPermitRootLogin
Copy after login
Copy after login

             

web security

1. sql injection

By inserting SQL commands into Web form submissions or entering domain names or query strings for page requests, the server is ultimately tricked into executing malicious SQL commands.

Defense: First filter, then perform parameter binding.

2. XSS

Cross Site Scripting

Principle: Embed scripts into web pages in different ways to achieve attack purposes.

Defense: Filter input.

$id = (int) $_REQUEST['id'];if( $id > 0 ){}
Copy after login
Copy after login
$name = htmlentities($_REQUEST['name'], ENT_QUOTES, "UTF-8");// 注意,如果这里不进行转化也是可以的,// 只要在输出的时候进行转化(建立在已经参数绑定的情况下)。
Copy after login
Copy after login
3. CSRF

##Cross-site request forgery Cross-site request forgery

Principle: Helen logged into Weibo and then browsed a harmful site. A fake post on Weibo was forged on the harmful site. At this time, Helen posted a Weibo without knowing it.

Defense: Embed a random token in the Weibo page, and the Weibo server verifies the token value.

4. Clickjacking

ClickJacking

原理:大概有两种方式,一是攻击者使用一个透明的 iframe ,覆盖在一个网页上,然后诱使用户在该页面上进行操作,此时用户将在不知情的情况下点击透明的 iframe 页面;二是攻击者使用一张图片覆盖在网页,遮挡网页原有位置。

防御:使用 js 判断框架是否在同一个域名下。添加头部指令: X-Frame-Options。

// js if (top.location.hostname !== self.location.hostname) {    alert("您正在访问不安全的页面,即将跳转到安全页面!");    top.location.href = self.location.href;}// Apache 配置:Header always append X-Frame-Options SAMEORIGIN// nginx 配置:add_header X-Frame-Options SAMEORIGIN;
Copy after login
Copy after login

5. 上传文件

原理:可能会被上传各种类型的非法软件。

防御:检测类型,检测大小。

6. zip *

原理:有些 zip 文件看起来很小,解压后非常大

防御:不要做这样的操作:对用户上传的压缩文件解压,处理,再压缩。因为你解压的时候,很可能你的服务器就被挤爆了。

7. session 劫持

原理:客户端和服务端通信时候,黑客抓包,获取 sessionid ,最终黑客与服务器通信。

防御:
 设置 HttpOnly,时常重设 sessionid。

8. 密码存储

$hashedPassword = password_hash('password', PASSWORD_DEFAULT);password_verify('the wrong password', $hashedPassword); // falsepassword_verify('my super cool password', $hashedPassword); // true
Copy after login
Copy after login

9. 暴力破解

/**防御:1. 限制次数2. 验证码3. 防火墙分析 类似 fail2ban*/
Copy after login
Copy after login

服务器安全

1. 修改 22 端口

vi /etc/ssh/sshd_configfirewall-cmd --list-allfirewall-cmd --add-port=8888/tcp --permanentfirewall-cmd --reload# 如果是阿里云服务器,不要忘记修改阿里云安全组
Copy after login
Copy after login

2. 修改 mysql root 名称

# 修改 mysql 数据库中的 user 表,然后 flush privileges
Copy after login
Copy after login

3. 禁止 root 远程登陆

vi /etc/ssh/sshd_configPermitRootLogin
Copy after login
Copy after login

相关推荐:

PHP安全地上传图片

PHP安全开发库详解

php安全配置记录和常见错误的详细总结介绍

The above is the detailed content of Detailed explanation of PHP security examples. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Roblox: Bubble Gum Simulator Infinity - How To Get And Use Royal Keys
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
Nordhold: Fusion System, Explained
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
Mandragora: Whispers Of The Witch Tree - How To Unlock The Grappling Hook
3 weeks ago By 尊渡假赌尊渡假赌尊渡假赌

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

Hot Topics

Java Tutorial
1672
14
PHP Tutorial
1276
29
C# Tutorial
1256
24
PHP vs. Python: Understanding the Differences PHP vs. Python: Understanding the Differences Apr 11, 2025 am 12:15 AM

PHP and Python each have their own advantages, and the choice should be based on project requirements. 1.PHP is suitable for web development, with simple syntax and high execution efficiency. 2. Python is suitable for data science and machine learning, with concise syntax and rich libraries.

PHP: A Key Language for Web Development PHP: A Key Language for Web Development Apr 13, 2025 am 12:08 AM

PHP is a scripting language widely used on the server side, especially suitable for web development. 1.PHP can embed HTML, process HTTP requests and responses, and supports a variety of databases. 2.PHP is used to generate dynamic web content, process form data, access databases, etc., with strong community support and open source resources. 3. PHP is an interpreted language, and the execution process includes lexical analysis, grammatical analysis, compilation and execution. 4.PHP can be combined with MySQL for advanced applications such as user registration systems. 5. When debugging PHP, you can use functions such as error_reporting() and var_dump(). 6. Optimize PHP code to use caching mechanisms, optimize database queries and use built-in functions. 7

PHP and Python: Comparing Two Popular Programming Languages PHP and Python: Comparing Two Popular Programming Languages Apr 14, 2025 am 12:13 AM

PHP and Python each have their own advantages, and choose according to project requirements. 1.PHP is suitable for web development, especially for rapid development and maintenance of websites. 2. Python is suitable for data science, machine learning and artificial intelligence, with concise syntax and suitable for beginners.

PHP in Action: Real-World Examples and Applications PHP in Action: Real-World Examples and Applications Apr 14, 2025 am 12:19 AM

PHP is widely used in e-commerce, content management systems and API development. 1) E-commerce: used for shopping cart function and payment processing. 2) Content management system: used for dynamic content generation and user management. 3) API development: used for RESTful API development and API security. Through performance optimization and best practices, the efficiency and maintainability of PHP applications are improved.

The Enduring Relevance of PHP: Is It Still Alive? The Enduring Relevance of PHP: Is It Still Alive? Apr 14, 2025 am 12:12 AM

PHP is still dynamic and still occupies an important position in the field of modern programming. 1) PHP's simplicity and powerful community support make it widely used in web development; 2) Its flexibility and stability make it outstanding in handling web forms, database operations and file processing; 3) PHP is constantly evolving and optimizing, suitable for beginners and experienced developers.

PHP and Python: Different Paradigms Explained PHP and Python: Different Paradigms Explained Apr 18, 2025 am 12:26 AM

PHP is mainly procedural programming, but also supports object-oriented programming (OOP); Python supports a variety of paradigms, including OOP, functional and procedural programming. PHP is suitable for web development, and Python is suitable for a variety of applications such as data analysis and machine learning.

PHP vs. Other Languages: A Comparison PHP vs. Other Languages: A Comparison Apr 13, 2025 am 12:19 AM

PHP is suitable for web development, especially in rapid development and processing dynamic content, but is not good at data science and enterprise-level applications. Compared with Python, PHP has more advantages in web development, but is not as good as Python in the field of data science; compared with Java, PHP performs worse in enterprise-level applications, but is more flexible in web development; compared with JavaScript, PHP is more concise in back-end development, but is not as good as JavaScript in front-end development.

PHP and Python: Code Examples and Comparison PHP and Python: Code Examples and Comparison Apr 15, 2025 am 12:07 AM

PHP and Python have their own advantages and disadvantages, and the choice depends on project needs and personal preferences. 1.PHP is suitable for rapid development and maintenance of large-scale web applications. 2. Python dominates the field of data science and machine learning.

See all articles