7 ms·
> Your website is automatically protected against XSS, session hijacking, CSRF, SQL injection, host header attacks, and other vulnerabilities. That's quite mis
by janmo 3y ago
> Your website is automatically protected against XSS, session hijacking, CSRF, SQL injection, host header attacks, and other vulnerabilities.
That's quite misleading however
- nstart 3y agoJust made the same comment and deleted it seeing that you already stated it. Protecting against all of these is hard and no tech is going to automatically protect for all of this on its own. Such a weird statement to make that takes away from the message of the site entirely.
- jszymborski 3y agoThe code snippet is very Laravel, and it does a lot to stop all those attacks with that API.
- janmo 3y agoI worked for a company and we used the PHP ORM Propel. So in theory no SQL injections you would think, WRONG. We used a function like findOne() (I don't recall exactly). It looked like this: $resetTokens->findOne($GET['password-reset-token']); The issue was that findOne would accept wildcards, so one could use ?password-reset-token=% in the URL and reset the password of any random users.
- blindhippo 3y ago... why would you pass $GET through to a logical layer with access to a data store write without sanitizing it? This seems like a pretty basic thing to fix, but then I only have your snippet to go by.
- oefrha 3y agoThat’s a parametrized API that’s supposed to be safe against injection, at least to anyone who’s ever used parametrized APIs and hasn’t read the documentation of this particular library in detail. That it supports wildcard makes as much sense as log4j executing code in textual messages. If an ORM/builder casually puts =/IS and LIKE in the same method, don’t touch it.
- creamyhorror 3y agoI think the webpage is talking specifically about Laravel. It ambiguously doesn't mention Laravel till later, but the code snippet looks like Laravel code. Laravel's ORM does sanitise strings. The snippet also validates request inputs, so clearly it doesn't assume that inputs are safe.
- _the_inflator 3y agoI totally agree with everyone before me here on the issue of security. If an app stands the stress test against say for example this comprehensive list(1), it can consider itself somewhat safe or at least benchmarked. Otherwise, only vague and unsubstantiated claims, which does not help PHP nor any other programming language or framework. [1] https://github.com/payloadbox/xss-payload-list https://github.com/payloadbox/xss-payload-list
- hk1337 3y agoIn both Symfony and Laravel these days they have their own request objects to help you get information on the request. You shouldn’t be reaching into the get or post variables directly like that. i.e. $request->query(‘password-reset-token’);
- cutler 3y agoRails does a pretty good job.
- hk1337 3y agoPHP has come a long way and I have since changed my mind about Laravel but I love Ruby, and Rails does an awesome job. Laravel actually seems to try to mimick Rails in PHP
- Alifatisk 3y agoI've tried Laravel, it's a beautiful framework. But I see no reason to switch from Rails, it's a beast.
- 0xblinq 3y agoHi! I'm looking for advice on how Rails vs Laravel compare (as I'll have to pick one of them soon for a project). Assuming the same knowledge and familiarity on both of them, why would you prefer Rails over Laravel? Thanks!
- Alifatisk 3y agoThe reason why I stuck with Rails is because I am already a Ruby user. I like PHP and all but I am way more comfortable with Ruby. I don’t think there is anything Rails can do that Laravel cannot and wise versa. It’s about taste. I think Rails + hotwire hit the sweetspot for me!
- 0xblinq 3y agoThanks!
- nstart 3y agoIn general I think there’s something to be said for sticking with languages that match your model of approaching a problem. DHH gave a good, albeit a bit rambly, keynote on this topic once. He compared some of the tools selection conversations to the equivalent of people comparing gaming consoles purely by specs when in reality, picking a console mostly boiled down to what you subjectively enjoyed more. I like that idea as a rule of thumb and encourage people to start there and go with what feels right for them before making deeper choices. (Lots of nuance here, don’t want to delve too deep so please view from that context :) )
- zemnmez 3y agoI want to second this. The top StackOverflow comment for protecting against XSS in PHP still recommends htmlspecialchars() https://stackoverflow.com/questions/1996122/how-to-prevent-xss-with-html-php https://stackoverflow.com/questions/1996122/how-to-prevent-x... which is a terrible and ancient approach (context-aware templates are the modern approach). I also Googled to check CSRF protection and all the sites I can find just discuss rolling it yourself; the example uses some CSPRNG that can potentially return not cryptographically secure numbers without erroring. https://www.section.io/engineering-education/csrf-protection-in-php/#step-2-render-contact-form-with-csrf-token https://www.section.io/engineering-education/csrf-protection... That's one thing that really drove me away from PHP. It presents an extremely simple seeming universe, in which web apps are very easy to write – but has really naïve bones, requiring a lot of extra scaffolding to be safe.
- deanc 3y agoYou don't get XSS protection out the box from any language's standard library, nor CSRF.
- zelphirkalt 3y agoWell, of course not from any lang that treats HTML as a string, but there are langs, which treat HTML as structured data, in their standard libraries. Take a look at SXML libraries for example. Whatever script you stored as a username for example, it would still get treated as text, not tag, when put into lets say a span or p. SXML is aware of the boundary between tags, their attributes and their content.
- deanc 3y agoI googled SXML and it appears to be have implementation libraries in lots of languages. This is not the core language's standard library.
- zelphirkalt 3y agoWhat do you put as the distinguishing feature between "core language standard library" and "comes with the language at installation"? Some example: https://www.gnu.org/software/guile/manual/html_node/Reading-and-Writing-XML.html https://www.gnu.org/software/guile/manual/html_node/Reading-... (no installation of anything third party required)
- notresidenter 3y agoI think the easier way to do things is mostly always the secure way in Laravel, so unless you go out of your way to do something weird, you're mostly safe from those attacks once you know how it works under the hood (to some extent) and what Laravel does and does not do for you.
- o1y32 3y ago[flagged]