Advanced Search
Start Your Free Trial

Overview

Other Readers Also Read...

Top Sellers in this Category

Cloud Security and Privacy, 1st Edition

Cloud Security and Privacy, 1st Edition
by Tim Mather; Subra Kumaraswamy; Shahed Latif

Apache Cookbook, 2nd Edition

Apache Cookbook, 2nd Edition
by Rich Bowen; Ken Coar

PHP Cookbook, 2nd Edition

PHP Cookbook, 2nd Edition
by Adam Trachtenberg; David Sklar

This is the Safari online edition of the printed book.

Easy, Powerful Code Security Techniques for Every PHP Developer

Hackers specifically target PHP Web applications. Why? Because they know many of these apps are written by programmers with little or no experience or training in software security. Don’t be victimized. Securing PHP Web Applications will help you master the specific techniques, skills, and best practices you need to write rock-solid PHP code and harden the PHP software you’re already using.

Drawing on more than fifteen years of experience in Web development, security, and training, Tricia and William Ballad show how security flaws can find their way into PHP code, and they identify the most common security mistakes made by PHP developers. The authors present practical, specific solutions–techniques that are surprisingly easy to understand and use, no matter what level of PHP programming expertise you have.

Securing PHP Web Applications covers the most important aspects of PHP code security, from error handling and buffer overflows to input validation and filesystem access. The authors explode the myths that discourage PHP programmers from attempting to secure their code and teach you how to instinctively write more secure code without compromising your software’s performance or your own productivity.

Coverage includes

  • Designing secure applications from the very beginning–and plugging holes in applications you can’t rewrite from scratch

  • Defending against session hijacking, fixation, and poisoning attacks that PHP can’t resist on its own

  • Securing the servers your PHP code runs on, including specific guidance for Apache, MySQL, IIS/SQL Server, and more

  • Enforcing strict authentication and making the most of encryption

  • Preventing dangerous cross-site scripting (XSS) attacks

  • Systematically testing yourapplications for security, including detailed discussions of exploit testing and PHP test automation

  • Addressing known vulnerabilities in the third-party applications you’re already running

Tricia and William Ballad demystify PHP security by presenting realistic scenarios and code examples, practical checklists, detailed visuals, and more. Whether you write Web applications professionally or casually, or simply use someone else’s PHP scripts, you need this book–and you need it now, before the hackers find you!

Amazon.com® Reader Reviews (Ranked by Helpfulness)

Average Amazon.com® Rating: 4.0 out of 5 rating Based on 3 Ratings

Great Book for PHP Developers - 2009-03-04
Reviewer Rating: 1 star rating2 star rating3 star rating4 star rating5 star rating
Securing PHP Web Applications is a great book for any PHP developer with an interest in writing better web applications. It covers a wide range of security topics that every developer should be familiar with. It would be useful for anyone hiring a PHP developer to know the concepts outlined in this book to aid in assessing a developers ability. The book introduced me to some new methods of testing web applications that I had not heard of before. Not the best book to hand to a security professional but a great book to hand to any developer lacking in the security department.

Not what I expected from a Security focused book - 2009-11-17
Reviewer Rating: 1 star rating2 star rating3 star rating4 star rating5 star rating
The author doesn't get into the intestines of PHP security breaches. This book has some good examples for beginners with very pristine knowledge of PHP security at all. If you plan to maintain a better security system or even to gain knowledge on more elaborate, extensive infringements, this book will not deliver the goods. Technically, for a book on PHP, the author focuses way too much on IIS server-security, which is 90% irrelevant to PHP programmers.

The book guides you through building and strengthening a guest-book for a website. Now in spite of guest-books being almost extinct, this is a very simple example of PHP code, which plausibly doesn't require any intricate security mechanism. Hence the author almost excuses herself for not having gone TOO DEEP on security. Nevertheless, the author does not spare the reader when she verbosely describes general security topics.

If the author had indeed chosen to focus on a more implementable example and demonstrate viable security through and through, this would've been a really great book. So, if you're looking for more than Guest-Book intricacy, find something else.

Got Hackers? This book will help you eliminate those pesks. - 2009-10-31
Reviewer Rating: 1 star rating2 star rating3 star rating4 star rating5 star rating
I'm reading this book and several others on safari books online. I found it so good I thought I might as well share with amazon users how useful this book is. If you are developing any application in PHP and you plan to put it online you need to read this book. This book really opened my eyes to how dangerous PHP is without the proper security. I most definitely would recommend this book. I'm sure like any book not every little command and possibility is covered but it sure helps you gain an upper hand in security you most likely didn't have before reading the book.

Browse Similar Topics

Top Level Categories:
Internet/Online
Security

Sub-Categories:
Internet/Online > PHP
Security > Internet/Online

Some information on this page was provided using data from Amazon.com®. View at Amazon >


About Safari Books Online • Terms of Service • Privacy Policy • Contact Us • Corporate Licenses • Help • Accessibility | See us on FacebookSee us on Linked InSee us on TwitterRSS

Copyright 2010 Safari Books Online. All rights reserved.