Go Back   Cloud Computing > Support > MySQL Issues.
 

Reply
 
Thread Tools Display Modes
  #1 (permalink)  
Old 07-01-10, 12:01
BOD Member
 
Join Date: Jun 2010
Posts: 50
Default How secure is this?

I have a website with user-generated comments/testimonials (each on a separate page). There's a simple form that asks for the name, comment, and some other information. When the form is submitted, a variable marked "moderated" is set to 0. The comment won't show up on the website until the "moderated" variable has been set (by hand) to 1 in phpMyAdmin. This way I can make sure that comments are appropriate and that nobody is trying to insert unwanted code/commands.

Is this secure enough?
Reply With Quote
  #2 (permalink)  
Old 07-01-10, 19:00
carl owen's Avatar
Super Moderator
 
Join Date: Nov 2008
Posts: 1,061
Default

Well, if the comments or testimonials posted are to be published manually, the form can be considered as secure enough, however, it would be a better option to use Secure Form Mailer Plugin For Wordpress (if you are using Wordpress) or a similar script which includes many security features including protection against email header injection
Reply With Quote
  #3 (permalink)  
Old 07-02-10, 14:45
BOD Member
 
Join Date: Jun 2010
Posts: 50
Default

Does the plugin work with MySQL, or does it just allow forms to be sent by email? I don't currently have the entries sent to my email; they go straight into the database. Saves me some time.
Reply With Quote
  #4 (permalink)  
Old 08-12-10, 07:42
BOD Member
 
Join Date: Jul 2010
Posts: 51
Default

Sorry I don't know if the WordPress plugin will work with MySQL but if it does I really recommend it. The range of features is really useful, especially the multiple language option. It works great at the basic level and if you want more then you can customise it easily enough. Bonus point to them for having added ReCaptcha!
Reply With Quote
  #5 (permalink)  
Old 11-21-10, 13:41
BOD Member
 
Join Date: Aug 2010
Posts: 50
Default I think so

I think the WordPress plugin will work with MySQL. I am pretty sure that WordPress fully supports this, and that makes it the best choice. I could be wrong, but this is the impression I have.
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off
Forum Jump


All times are GMT -6. The time now is 00:43.

Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
Copyright © 1999-2012, BODHost Ltd. All rights reserved.