Solved

phpids integration and usage

Posted on 2013-07-01
7
249 Views
Last Modified: 2013-08-04
Hi EE,

Please do let me know steps to integrate phpids and how to verify if its working and monitor the attacks.
0
Comment
Question by:Insoftservice
  • 4
  • 2
7 Comments
 
LVL 52

Assisted Solution

by:Julian Hansen
Julian Hansen earned 300 total points
ID: 39289526
I would start with reading the FAQ
https://phpids.org/faq/
0
 
LVL 15

Author Comment

by:Insoftservice
ID: 39289637
@julianH i tried with but was not completely successful.
Please do let me know whether we have some API which would not only detect attacks but also avoid it.PHPIDS detects all sorts of XSS, SQL Injection, header injection, directory traversal, RFE/LFI, DoS and LDAP attacks. But it does not prevent it.

Is there some api which does both specially sql injection.
0
 
LVL 108

Assisted Solution

by:Ray Paseur
Ray Paseur earned 200 total points
ID: 39289748
I would probably approach this from a different perspective, especially since it's at level 0.7 and since I got the "Untrusted Connection" warning when I tried to visit the phpids link.

Instead of trying to enumerate the threats and attacks, just switch your thinking to the security mantra: Accept Only Known Good Values.  To be sure, there are still attacks that can be mounted against thoughtfully secured web sites, but they are far less likely to succeed if your script tests every external input for "reasonable" values and simply ignores the ones that fail the reasonability tests.

This link (and the whole organization) may be useful.  If you're not a member, join!
https://www.owasp.org/index.php/SQL_Injection_Prevention_Cheat_Sheet
0
Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

 
LVL 15

Author Comment

by:Insoftservice
ID: 39292202
0
 
LVL 15

Author Comment

by:Insoftservice
ID: 39369133
c
0
 
LVL 52

Accepted Solution

by:
Julian Hansen earned 300 total points
ID: 39369276
Is there some api which does both specially sql injection.
Don't look for an API to do this for you - to prevent SQL injection code your page and queries correctly.

Use either mysqli or PDO

A) Put all data to go to database through mysqli_real_escape_string (in the case of mysqli
B) Use prepared statements
0
 
LVL 15

Author Closing Comment

by:Insoftservice
ID: 39380283
Issue had got already resolved, but the suggestion was also up-to the mark to resolve and tackle my questions more easily thx to all
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Generating table dynamically is the most common issue faced by php developers.... So it seems there is a need of an article that explains the basic concept of generating tables dynamically. It just requires a basic knowledge of html and little maths…
Deprecated and Headed for the Dustbin By now, you have probably heard that some PHP features, while convenient, can also cause PHP security problems.  This article discusses one of those, called register_globals.  It is a thing you do not want.  …
Learn how to match and substitute tagged data using PHP regular expressions. Demonstrated on Windows 7, but also applies to other operating systems. Demonstrated technique applies to PHP (all versions) and Firefox, but very similar techniques will w…
This tutorial will teach you the core code needed to finalize the addition of a watermark to your image. The viewer will use a small PHP class to learn and create a watermark.

919 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now