<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PHP Security Guide &amp; Checklist for Websites and Web Applications &#8211; Bottom Line for Every Good PHP Developer</title>
	<atom:link href="http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html</link>
	<description>Just another dumbass webmaster, goofing around...</description>
	<lastBuildDate>Wed, 08 Feb 2012 09:57:05 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/comment-page-1#comment-16403</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Mon, 02 Jan 2012 11:20:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html#comment-16403</guid>
		<description>[...]  [...]</description>
		<content:encoded><![CDATA[<p>[...]  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rajesh singh</title>
		<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/comment-page-1#comment-15612</link>
		<dc:creator>rajesh singh</dc:creator>
		<pubDate>Wed, 12 Oct 2011 06:00:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html#comment-15612</guid>
		<description>thank you very much

i have got very important things about PHP from you thank you, thank you and thank you</description>
		<content:encoded><![CDATA[<p>thank you very much</p>
<p>i have got very important things about PHP from you thank you, thank you and thank you</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sboniso</title>
		<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/comment-page-1#comment-15518</link>
		<dc:creator>Sboniso</dc:creator>
		<pubDate>Wed, 31 Aug 2011 11:07:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html#comment-15518</guid>
		<description>Thank you man. Now my application will be more secure.</description>
		<content:encoded><![CDATA[<p>Thank you man. Now my application will be more secure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elumar</title>
		<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/comment-page-1#comment-14656</link>
		<dc:creator>Elumar</dc:creator>
		<pubDate>Fri, 08 Apr 2011 03:43:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html#comment-14656</guid>
		<description>This post is fantastic, thanks!</description>
		<content:encoded><![CDATA[<p>This post is fantastic, thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jae</title>
		<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/comment-page-1#comment-11574</link>
		<dc:creator>Jae</dc:creator>
		<pubDate>Fri, 10 Dec 2010 13:08:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html#comment-11574</guid>
		<description>Excellent Post! This is exactly what I was looking for. Thanks for sharing!</description>
		<content:encoded><![CDATA[<p>Excellent Post! This is exactly what I was looking for. Thanks for sharing!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Grace Roberts</title>
		<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/comment-page-1#comment-11273</link>
		<dc:creator>Grace Roberts</dc:creator>
		<pubDate>Tue, 16 Nov 2010 16:32:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html#comment-11273</guid>
		<description>This is awesome, thanks!

If any of you PHP geniuses are ever looking for PHP jobs check out http://www.technojobs.co.uk/jobs/php</description>
		<content:encoded><![CDATA[<p>This is awesome, thanks!</p>
<p>If any of you PHP geniuses are ever looking for PHP jobs check out <a href="http://www.technojobs.co.uk/jobs/php" rel="nofollow">http://www.technojobs.co.uk/jobs/php</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: R.J.</title>
		<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/comment-page-1#comment-10993</link>
		<dc:creator>R.J.</dc:creator>
		<pubDate>Mon, 20 Sep 2010 13:25:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html#comment-10993</guid>
		<description>Great summary of security threats and nice presentation of concepts. Thanks for sharing!</description>
		<content:encoded><![CDATA[<p>Great summary of security threats and nice presentation of concepts. Thanks for sharing!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Panda</title>
		<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/comment-page-1#comment-10821</link>
		<dc:creator>Panda</dc:creator>
		<pubDate>Wed, 01 Sep 2010 10:36:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html#comment-10821</guid>
		<description>Fantastico Post!!!

God Bless !!</description>
		<content:encoded><![CDATA[<p>Fantastico Post!!!</p>
<p>God Bless !!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Links recomendados AVLog &#124; AVLog - AgeValed</title>
		<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/comment-page-1#comment-10196</link>
		<dc:creator>Links recomendados AVLog &#124; AVLog - AgeValed</dc:creator>
		<pubDate>Fri, 16 Jul 2010 16:27:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html#comment-10196</guid>
		<description>[...] PHP Security Guide &amp; Checklist for Websites and Web Applications – Bottom Line for Every Good ... [...]</description>
		<content:encoded><![CDATA[<p>[...] PHP Security Guide &amp; Checklist for Websites and Web Applications – Bottom Line for Every Good &#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nicolas</title>
		<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/comment-page-1#comment-9901</link>
		<dc:creator>Nicolas</dc:creator>
		<pubDate>Thu, 20 May 2010 15:28:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html#comment-9901</guid>
		<description>Awesome post!
Exactly what every PHP programmer should know and follow, thanks for sharing your thoughts.

Nicolas.</description>
		<content:encoded><![CDATA[<p>Awesome post!<br />
Exactly what every PHP programmer should know and follow, thanks for sharing your thoughts.</p>
<p>Nicolas.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Useful Security Pages &#124; Toby&#39;s Development Blog</title>
		<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/comment-page-1#comment-9860</link>
		<dc:creator>Useful Security Pages &#124; Toby&#39;s Development Blog</dc:creator>
		<pubDate>Wed, 05 May 2010 08:43:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html#comment-9860</guid>
		<description>[...] Web App security checklist [...]</description>
		<content:encoded><![CDATA[<p>[...] Web App security checklist [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yang Yang</title>
		<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/comment-page-1#comment-9753</link>
		<dc:creator>Yang Yang</dc:creator>
		<pubDate>Tue, 06 Apr 2010 15:41:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html#comment-9753</guid>
		<description>Never use numerable values such as natural numbers to externally identify something though they are so easy to use in many cases. For example, better not use the ID of a record in any URL of your site. Instead, generate something that&#039;s not numerable so the attackers cannot jeopardize your site by both knowing something about its internal structure thus fabricating operations by unexpected input values and committing exhaustion attacks by navigating through all possible combinations of URL.</description>
		<content:encoded><![CDATA[<p>Never use numerable values such as natural numbers to externally identify something though they are so easy to use in many cases. For example, better not use the ID of a record in any URL of your site. Instead, generate something that&#8217;s not numerable so the attackers cannot jeopardize your site by both knowing something about its internal structure thus fabricating operations by unexpected input values and committing exhaustion attacks by navigating through all possible combinations of URL.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yang Yang</title>
		<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/comment-page-1#comment-8599</link>
		<dc:creator>Yang Yang</dc:creator>
		<pubDate>Wed, 10 Mar 2010 03:58:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html#comment-8599</guid>
		<description>Thanks for the very useful contribution. This guide serves as but a starting point of PHP security that doesn&#039;t intend to elaborate on each of the practices for potentially unlimited scenarios.

But that&#039;s for sure a really nice tip for escaping strings to be used in html attributes! Good lesson I&#039;ve learnt. Thanks!</description>
		<content:encoded><![CDATA[<p>Thanks for the very useful contribution. This guide serves as but a starting point of PHP security that doesn&#8217;t intend to elaborate on each of the practices for potentially unlimited scenarios.</p>
<p>But that&#8217;s for sure a really nice tip for escaping strings to be used in html attributes! Good lesson I&#8217;ve learnt. Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MugeSo</title>
		<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/comment-page-1#comment-8598</link>
		<dc:creator>MugeSo</dc:creator>
		<pubDate>Wed, 10 Mar 2010 03:03:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html#comment-8598</guid>
		<description>when you use escaped string as html attribute, you should supply 2nd argument to htmlentities, like:
htmlentities($str, ENT_QUOTES);
without 2nd argument, htmlentities won&#039;t escape single quote.
see: http://php.net/htmlentities

And  if you want to support i18n, the 3rd argument is also required.
without that, htmlentities treat input string as ISO-8859-1. So you must supply correct encoding.</description>
		<content:encoded><![CDATA[<p>when you use escaped string as html attribute, you should supply 2nd argument to htmlentities, like:<br />
htmlentities($str, ENT_QUOTES);<br />
without 2nd argument, htmlentities won&#8217;t escape single quote.<br />
see: <a href="http://php.net/htmlentities" rel="nofollow">http://php.net/htmlentities</a></p>
<p>And  if you want to support i18n, the 3rd argument is also required.<br />
without that, htmlentities treat input string as ISO-8859-1. So you must supply correct encoding.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yang Yang</title>
		<link>http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html/comment-page-1#comment-8559</link>
		<dc:creator>Yang Yang</dc:creator>
		<pubDate>Tue, 09 Mar 2010 07:26:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.kavoir.com/2010/03/php-security-checklist-for-websites-and-web-applications-bottom-line-for-every-good-php-developers.html#comment-8559</guid>
		<description>Thanks, wensheng. :)</description>
		<content:encoded><![CDATA[<p>Thanks, wensheng. :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

