Wattle Software - producers of XMLwriter XML editor
 Bookstore Home | XMLwriter Home | Search | Site Map 
XML Related
 General XML
 XSLT & Stylesheets
 XHTML
 SGML
 XML DTDs
 XML Schema
Web Development
 Web Graphics
 HTML
 Dynamic HTML
Web Services
 General Web Services
 UDDI
 SOAP
 WSDL
 Programming/Scripting 
 PHP Programming
 Perl Programming
 Active Server Pages
 Java Server Pages
 JavaScript
 VBScript
 .NET Programming
 
XMLwriter
 About XMLwriter
 Download XMLwriter
 Buy XMLwriter
XML Resources
 XML Links
 XML Training
 The XML Guide
 XML Book Samples
 

php|architect's Guide to PHP Security|


By Ilia Alshanetsky
 
Image of: php|architect's Guide to PHP Security|
Pricing Details:

List Price:$32.99
You save:$8.91 (27%)
Your Price:$24.08
Buy Now

Book Details:

Format:Paperback, 200 pages.
Publisher:Marco Tabini & Associates, Inc. 2005-09-05
ISBN:0973862106

Average Customer Rating:

4.5 4.5 out of 5 stars (7 reviews)

Editorial Reviews:

Security is a hot topic these days, with new exploits and patches released on a daily basis for all sorts of operating systems and applications.

Recently, the security bubble has expanded to touch the PHP world, and several well-known applications have been the target of a great number of attacks.

Despite all the negative publicity, however, PHP is and remains a very stable--and very secure--programming environment. php|architect's Guide to PHP Security, written by security expert (and frequent php|architect contributor) Ilia Alshanetsky, provides you with a guide that covers everything you need to secure existing PHP applications and write new ones with security in mind.

* Provides techniques for both PHP 4 and PHP 5
* Includes a step-by-step guide to securing your applications
* Provides comprehensive coverage of security design
* Teaches you how to defend yourself from hackers
* Shows you how to distract hackers with a "tar pit" to help you fend off potential attacks

Rather than drowning you in overlong explanations, this book focuses on providing you with accurate information on proper security techniques, and showing you a step-by-step approach to writing applications that are stable, secure and reliable.


Customer Reviews:

Displaying 1 to 5 of 7 total reviews (Page 1 of 2):

4 out of 5 stars Excellent broad strokes coverage

Overall, an excellent resource for security. It's small size means that that topics are narrow enough to be digested and acted upon individually.

3 out of 5 stars An OK book, but lots of errors and examples weren't great

As a programmer with 7 years experience, I already had a fair amount of knowledge about PHP security, but it was all self-taught. I will say that I was able to learn a few new things and pick up a few strategies from this book.

Overall, I wouldn't say I was disappointed with the book, but I definitely wasn't impressed. There were numerous misspellings, typos, and (in a few cases) words missing altogether. With my knowledge I considered these typos to be fairly minor, but someone with less experience may become confused by a few of them.

In one case, a variable in one of the coding examples was actually mis-keyed. If someone were to copy the example verbatim, it would not behave as expected. That type of error should never occur in a book like this.

The various chapters do contain useful information, but the code examples are pretty lame. Don't buy this book if you're looking for specific, real-world, useful examples on how to implement your security measures, but if you already have enough PHP experience to figure out ways of implementing the *concepts* presented in this book, then it may be worthwhile picking up.

Experienced PHP programmers with some security experience will probably find a few useful tidbits, and anyone looking to truly maximize the security of their web applications would definitely benenfit from the sheer number of concepts presented in this book. However, many PHP developers will likely agree that a number of the concepts presented are somewhat superfluous, or rendered obsolete by other concepts.

In many cases the author will provide a concept for securing an application, provide an example of how to do it, and then proceed to explain why that method is NOT the best method to use. Someone looking for a quick-use reference manual of the most effective ways to secure your application will probably not enjoy this book.

BOTTOM LINE: there's gotta be better books on PHP security available for beginners, intermediate developers, and professionals alike. Only buy this book if you're interested in a large number of concepts and don't care about clear and specific examples of real-world implementation.

Advice to the Author/Publisher: Fix the typos and put the missing words back in! Expand on your code examples and provide more real-world application. Choose better naming conventions for your variables in your examples - no one wants to guess at what the variable "$e" represents, use "$elements" instead. Compile a chapter of "Top 10 security exploits and how to avoid them" using your recommended methods for the various exploits (or something similar). As it stands now, your readers not only have to work through the errors and the poor examples, they also have to decode which of your concepts are worth actually implementing, since so many of them have loopholes, provide other vulnerabilities, or simply "aren't enough" to truly secure the application.

5 out of 5 stars Concise, comprehensive, essential

After a website of mine was hacked I decided I needed to be better informed about php/mysql security, so I bought this book. I now refer to it very frequently. It seems short but there's no fluff and it's right to the point. The author clearly understands the internals of php, apache and mysql very well. If you're writing php, this book is essential on your bookshelf.

4 out of 5 stars Great Book For Beginners

This book was real helpful. I really didn't know much about the topics so I found it a good introduction. If you are even semi-knowledgeable about this area, I would recommend another book.

5 out of 5 stars Best of the Best

Best of the best of all other books i've read about PHP Security. Easily comprehensible (even for a frenchy like me), no bla-bla, explanations which are not limited to a surface layer but go deeply under the hood (Paranoid attitude says Milos), examples of code which are limpid, simple to understand, include, and implement ...
The author have knowledge of the inner working procedure of PHP, and it makes the difference with others books or compilation of articles found on the Net. Yes, this book is thin, yes, it has only 10 chapters, and yes, i have found immediately what i was waiting for a long time.
Buy it, steal it, hack it, but if you write PHP app, you must read this book.

Four thumbs up (the hands and the feet)

More Customer Reviews:
Next Page


Customers who bought this book were also interested in:


Essential PHP Security


Pro PHP Security


AJAX and PHP: Building Responsive Web Applications


PHP 5 Objects, Patterns, and Practice


PHP|Architect's Guide to PHP Design Patterns

 

Find similar books by category...


Search for more:

Search books:  



Google
 
Web XMLwriter.net




Last updated: Sat Nov 22 18:37:22 CST 2008
© Wattle Software 2007. All rights reserved.