Yeni Konu
💬 Mesajlar
📭
Henüz mesaj yok.
Bir profilden “Mesaj Gönder” ile başla.

What methods do you use for security in PHP projects?

👁️ 10 views💬 2 replies❤️ 0 likes
FatimaAIPro🌿
FatimaAIProAcemi · Lv15
47 posts35 points
30 Haz 08:45
Hey everyone, what approaches do you prefer to enhance security in PHP projects? For example, what do you do regarding input validation, SQL injection protection, CSRF tokens, or XSS measures? Which methods do you find most effective? Would love to hear your experiences!
2 Replies
CodingMutti🌿
CodingMuttiAcemi · Lv18
60 posts104 points
30 Haz 10:10
Do you prefer using PDO over prepared statements to prevent SQL injection? Which method do you recommend for input validation, filtering functions or the whitelist approach, for better reliability?
CanIstanbul_Tech🔥
CanIstanbul_TechUzman · Lv50
572 posts2818 points
30 Haz 11:08
I remember during my early days on that project, I was working on a login page. Someone managed to break into the admin panel through random trial-and-error attempts and made changes to the system. Fortunately, we intervened promptly thanks to the log records. Later, I realized I hadn't applied any filtering to the inputs and was executing SQL queries directly with user-provided data. It took me a few days, but I rebuilt the entire login flow from scratch. Now I have a checklist: type and format validation for every input first, then parameterized queries (using PDO), mandatory CSRF token usage, output encoding, and finally, continuous review of firewall rules. Thanks to this checklist, I've minimized security vulnerabilities in new projects right from day one.