Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8113143
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 6, 20262026-06-06T02:44:01+00:00 2026-06-06T02:44:01+00:00

[I hope that this question is not too broad, I think that the subject

  • 0

[I hope that this question is not too broad, I think that the subject is very interesting but I incourage you to tell me if it’s off-policy.]

My scenario is this:

  • I have a LAMP website who stores also sensitive data and documents
  • Only registered users are allowed to operate on the site, and only on certain data and documents. Users are stored in $_SESSION variables
  • Most of the pages implement a sort of rudimental permission control, but some important DB operations are called via AJAX
  • AJAX security is implemented very poorly, as anyone that is that smart can tamper with the request sending whatever id they like and delete records with brutal simplicity

Asking for a complete book on security is obviously a bit too much (and I’m already reading and trying a lot on the subject), let’s say that my main concern is if AJAX pages should be treated with special regards, as I need to secure the whole software to prevent hacks and other problems.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-06T02:44:03+00:00Added an answer on June 6, 2026 at 2:44 am

    I have a LAMP website who stores also sensitive data and documents

    You should store as little sensitive data as possible. Especially when you are not sure how to keep this information secure/private. Use OpenID or something for your authentication for example. I really like LightOpenID for it’s simplicity. I created a little example project/library to see lightopenId in use. It simplifies using OpenID by using openID-selector. When you use OpenID you also use secure OpenID providers the passwords are also not transmitted over the wire in plain-text but protected by https/SSL.

    Only registered users are allowed to operate on the site, and only on
    certain data and documents. Users are stored in $_SESSION variables

    Yup that’s what sessions are for.

    Most of the pages implement a sort of rudimental permission control,
    but some important DB operations are called via AJAX

    You should read up on OWASP top 10. at least. (Don’t stop at 10.)

    AJAX security is implemented very poorly, as anyone that is that smart
    can tamper with the request sending whatever id they like and delete
    records with brutal simplicity

    See previous section. Read up on OWASP top 10 section at least. Somethings which a lot of people overlook for example are CSRF for example.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Not too sure how to formulate my question and I hope that this is
I hope this question is not too off-topic, if it is this post can
I hope this question is not too silly, but what is the most basic
I hope this question does not come off as broad as it may seem
I hope this question is not considered too basic for this forum, but we'll
I hope this question isn't too dumb. We have many websites internally that need
I hope this question isn't too general. Well, the situation is that I am
This is my first question on the site and I hope it's not too
I hope I'm not being too long winded in this question, I just want
This is a very simple, probably too simple question but I'm afraid my limited

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.