Re: Web security issue help

Raakesh kumar <[email protected]>
Newsgroups gmane.user-groups.linux.delhi
Message-ID <CAEid6wEnoOzx5+DFQLsMZ2ADuhN1+7cP3yejfMzXnpj9qA1MXg@mail.gmail.com>
Thank you all for your valuable suggestions. We have successfully recovered
the website, changed credentials and going to take extra precautions from
now onward.
@Ravi, what and whom did you report?


On Tue, Jun 25, 2013 at 6:56 PM, Vivek Puri <[email protected]>wrote:

> Hi Raakesh,
>
>  we have a website http://www.brahmabooks.com which is developed in core
>> php
>> without any framework or anything. Today someone mailed us with few user
>> details saying that he has hacked our system.
>> Now i don't understand how
>> could someone display all details from our database.
>>
> Once a hacker gains access to your database, this is simple for him.
>
>  We have used PHP PDO
>> with parameterized query and have tested against lots of sql injection
>> techniques and found it injection proof. I found that Cookies are not
>> encrypted and are stored in plain data which i have to take care of but is
>> it possible to get table columns and data with this detail?
>> Can someone guide me how can i secure it and how he would have got these
>> details?
>>
>>  Security can be broken from many different ways, usually referred as
> attack vectors.
> SQL Injection is one of the attack vector, there could potentially be many.
>
> Just using PHP PDO with parametrized query, reduces risk but doesn't mean
> it makes
> it immune. To secure the application you have to secure the OS, web
> server, php,
> database, your own code.
>
> Most people prefer using some kind of framework specifically for this
> reason that
> a popular framework is used by many and have been reviewed for security.
> Still
> that doesn't means its bullet proof , just that its better than baking
> your own
> code specially if you do not fully understand the aspects of security.
>
> Here someone could only give you generic advice basically somethings you
> can find
> doing a quick google search also:
>
> - Is your OS secure ? Make sure all non essential services are stopped
> - Make sure you have latest security patches applied.
> - Is database running on secure or local port ? If not switch to local
> port.
> - How complex is the code ? Can you move to using some PHP framework or
> CMS ?
> - Can you hire someone to review your code?
>
> Once you find answer to these questions you may have better clarity.
>
> rgds
> vivek
>
> --
> http://www.twitter.com/vivpuri | http://www.machint.com
>
>
> ______________________________**_________________
> Ilugd mailing list
> Ilugd-cunTk1MwBs8/[email protected]
> http://frodo.hserus.net/**mailman/listinfo/ilugd<http://frodo.hserus.net/mailman/listinfo/ilugd>
>



-- 
Regards
RAKESH KUMAR
http://raakeshkumar.wordpress.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.