/    Sign up×
Community /Pin to ProfileBookmark

PHP MySql Security Question

Hi All

I have been learning PHP and MySql. I have been learning how to fill out a form and use PHP to populate a database on MySql. I have also learned a bit about how to retrieve that information as a CSV for Excel. I am also going to us iFrame Tags to put a form on my clients Facebook page. I have learned enough that I believe I can make this happen. I am ready to take my skills to the next level.

My client’s Facebook page is already going viral and he is about to give away some high dollar items. A contest. So his Facebook page is going to explode with traffic. In order to enter the contest we are going to need to retrieve personal info, like name, email, address, etc.

I have security concerns. Since this is my first attempt at this, how secure is PHP and MySQL? If I use a username and password on my server that should be enough to protect personal information, right? I will be responsible for allot of personal information so I don’t want to screw this up. Am I over my head?

My second question. I need my client to be able to retrieve that information from the MySql database. I was thinking of creating a page that he can access to retrieve the personal information. But again, there is another security issue. I would probobaly need to password protect it. Is there a better way to do this?

Here is an example of what I am trying to do [URL=”http://www.facebook.com/Deergear?sk=app_156351054435971″]http://www.facebook.com/Deergear?sk=app_156351054435971[/URL]

Thanks for your help.?

to post a comment
PHP

4 Comments(s)

Copy linkTweet thisAlerts:
@NvenomJul 06.2011 — Would not be hard to make is secure just escape the query being sent to the DB and it would be just as easy to show information when the person enters in there email and password or something like that, if you decide to go forward i would recommend reading up on this Escaping and than go ahead with a form to grab there information based on 2 variables, or more but people usually don't like things to be complicated.
Copy linkTweet thisAlerts:
@NogDogJul 06.2011 — A fairly short, concise book that's well worth spending a couple evenings with (and then keeping near where you do your coding) is [url=http://phpsecurity.org/]Essential PHP Security[/url] by Shiflett.
Copy linkTweet thisAlerts:
@nubprogJul 07.2011 — MGUISE, have you had any luck with this? I am looking for some help on this and maybe just someone to do it for me. Anybody interested?
Copy linkTweet thisAlerts:
@chrisranjanaJul 09.2011 — Yes that is quite a good book. Also you can see what were the top 10 security loopholes of 2010 by going here https://www.owasp.org/index.php/Top_10_2010-Main
×

Success!

Help @MGuise spread the word by sharing this article on Twitter...

Tweet This
Sign in
Forgot password?
Sign in with TwitchSign in with GithubCreate Account
about: ({
version: 0.1.9 BETA 5.20,
whats_new: community page,
up_next: more Davinci•003 tasks,
coming_soon: events calendar,
social: @webDeveloperHQ
});

legal: ({
terms: of use,
privacy: policy
});
changelog: (
version: 0.1.9,
notes: added community page

version: 0.1.8,
notes: added Davinci•003

version: 0.1.7,
notes: upvote answers to bounties

version: 0.1.6,
notes: article editor refresh
)...
recent_tips: (
tipper: @AriseFacilitySolutions09,
tipped: article
amount: 1000 SATS,

tipper: @Yussuf4331,
tipped: article
amount: 1000 SATS,

tipper: @darkwebsites540,
tipped: article
amount: 10 SATS,
)...