Sunday, April 4, 2010

How to escape from the remote file inclusion attack

Answer

1. All user inputs must be strictly validated

2. Use mod_secrity module

3. register globals must be turned off

4. open_basedir must be set to the document root . it should not be no value.

No comments:

Post a Comment