Ask a Question related to Macromedia Exchange Dreamweaver Extensions, Design and Development.

  1. #1

    Default PHP security

    I have posted this question elsewhere by mistake - sorry.
    My ISP says that I most likely have a security hole in my website PHP coding.
    My website uses PHP to call pages, overall it was written using dreamweaver.
    I am not very familiar with either PHP or Dreamweaver, although I did write
    the website, so I have no one else to blame but myself.
    I have had a few rogue websites set up using my webspace. After deleting the
    sites and uploading the original files and changing my password they still
    arrived. My ISP says there is most likely a security hole in my PHP coding and
    I should apply the most recent patches.
    I don't know/understand how to do this, my ISP doesn't support PHP or any
    website building really.
    I am currently running the most recent version of PHP on my PC, but wasn't
    when I wrote the website. How do I update my web pages to be using this most
    recent version of PHP.
    If I only send simple code to my webspace is it not the ISP PHP parser that
    needs updating? (This probably shows my lack of knowledge)
    Any help would be gratfuly received.

    david@bridgemics.co. Guest

  2. Similar Questions and Discussions

    1. Change Flash Security Settings? Security ManagerOffline?
      Hello I have downloaded firefox and flash player, I have content which when I run it, flash blocks it wisely and reports that the page is trying...
    2. Error: code:Channel.Security.Error string:'Security
      Flex 2.0 beta 1 I created an mxml application with the following tag: <mx:WebService id="ws"...
    3. System.Security.SecurityException: Security error
      Dear All, The problem or error which I am getting while running my web application is as given below: Security Exception Description: The...
    4. Security tool to check CGI scripts for security holes/vulnerabities
      I'm searching for a good security tool that I can use regularly to scan all the programs/scripts in my web servers cgi-bin directory to identify...
    5. Asp.Net Security Analyser (new security tool by DDPlus)
      Hello I'm happy to announce that we (DDPlus) have just released the first stable version of our new Open Source Project: the Asp.Net Security...
  3. #2

    Default Re: PHP security

    David,

    The first thing that I would check is the directory/file permissions on your
    web space. If others are posting files there, they must be wide open.

    The subject of updating PHP is a little more complex than can be handled in
    this forum. You absolutely need to have an ISP that can assist you with
    this. In fact, I'm surprised that tou are able to use it at all if the ISP
    doesn't support it. How did you install it on the server?

    Could you provide a link to the site?

    Respectfully,

    Steve

    "david@bridgemics.co." <webforumsuser@macromedia.com> wrote in message
    news:g2jhnb$akv$1@forums.macromedia.com...
    >I have posted this question elsewhere by mistake - sorry.
    > My ISP says that I most likely have a security hole in my website PHP
    > coding.
    > My website uses PHP to call pages, overall it was written using
    > dreamweaver.
    > I am not very familiar with either PHP or Dreamweaver, although I did
    > write
    > the website, so I have no one else to blame but myself.
    > I have had a few rogue websites set up using my webspace. After deleting
    > the
    > sites and uploading the original files and changing my password they still
    > arrived. My ISP says there is most likely a security hole in my PHP coding
    > and
    > I should apply the most recent patches.
    > I don't know/understand how to do this, my ISP doesn't support PHP or any
    > website building really.
    > I am currently running the most recent version of PHP on my PC, but wasn't
    > when I wrote the website. How do I update my web pages to be using this
    > most
    > recent version of PHP.
    > If I only send simple code to my webspace is it not the ISP PHP parser
    > that
    > needs updating? (This probably shows my lack of knowledge)
    > Any help would be gratfuly received.
    >

    Steve Guest

  4. #3

    Default Re: PHP security

    Hi Steve,
    My ISP doesn't support PHP in as much as they won't help with any PHP
    problems, the webspace has PHP installed and enabled for use.
    My site is at [url]www.hebdensound.co.uk[/url]
    When you say file/directory permissions, is this beyond the ISP only allowing
    logged in users to ftp to a site?
    I have just now changed permissions to my directories to have a username and
    password, I am not sure how this gets envoked however, but is this what you
    mean? When I use an ftp program I can still get into these directories without
    any extra password.

    Thanks for your help



    david@bridgemics.co. Guest

  5. #4

    Default Re: PHP security

    David,

    I checked your site, and your FTP service is requesting a User ID and
    password. I suspect that you re getting in through as you've cached the
    authentication already. One way to check this is to clear your browser's
    cache/cookies and try logging in again. You should get prompted.

    This should stop users from posting files on your site unless you have
    created an upload page that they can access. I didn't see one when I looked
    at your site. You need to set the file/directory permissions on all of your
    directories so that the users can read/execute PHP pages, but not write. If
    you do create an upload page, point any uploads to a directory that can be
    written to by the users, but won't give them execute scripts permissions.
    Otherwise they can upload a script and then execute it, and then you're in
    trouble.

    The ISP needs to apply the latest patches to PHP on the server. This is not
    something you can do. If you upgrade PHP on your workstation, any changes
    that you make to yuour pages locally can be FTP'd to the server. However, if
    you are coding to a later version of PHP than the ISP, some of your pages
    may not work. I always try to stay in sync with the ISP to avoid this.

    From the sound of it, you would be much better off getting a different ISP.
    There are thousands out there, and most offer much better support than your
    current one.

    Steve

    "david@bridgemics.co." <webforumsuser@macromedia.com> wrote in message
    news:g2mqb3$40e$1@forums.macromedia.com...
    > Hi Steve,
    > My ISP doesn't support PHP in as much as they won't help with any PHP
    > problems, the webspace has PHP installed and enabled for use.
    > My site is at [url]www.hebdensound.co.uk[/url]
    > When you say file/directory permissions, is this beyond the ISP only
    > allowing
    > logged in users to ftp to a site?
    > I have just now changed permissions to my directories to have a username
    > and
    > password, I am not sure how this gets envoked however, but is this what
    > you
    > mean? When I use an ftp program I can still get into these directories
    > without
    > any extra password.
    >
    > Thanks for your help
    >
    >
    >

    Steve Guest

Posting Permissions

  • You may not post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139