Categories


Loading feed
Loading feed
Loading feed

PHP Security Tip #2


Security by obscurity is no security at all. On the other hand you don't want to give away information about your site either. Today's tip is a simple one but one that is often overlooked in production environments.

Make sure you do not display errors and potentially leak information about your site.

Simply setting display_errors = Off in your php.ini of your production server will prevent you from leaking information that may give intruders hints to the structure of your system. By default, display_errors = On.

You can find more information and error reporting options in the manual's Error Handling and Logging Functions Introduction section.

Comments


Friday, March 2, 2007
DEVZONE ERROR HANDLING
10:39AM PST · peehpee
AHHH NOTHING LIKE BEING HOISTED BY YOUR OWN PETARD
12:45PM PST · Cal Evans (editor)
Monday, April 16, 2007
FRENCH TRANSLATION
11:33PM PDT · neovov
Loading feed