20.07.2011 13:50
US-CERT: Security Recommendations to Prevent Cyber Intrusions
Die Kollegen vom US-CERT haben eine ganze Menge Ratschläge zur allgemeinen IT-Security herausgegeben, die wichtigsten auch hier:
- Ensure that the "allow URL_fopen" is disabled on the web server to help limit PHP vulnerabilities from remote file inclusion attacks.
- Limit the use of dynamic SQL code by using prepared statements, queries with parameters, or stored procedures whenever possible.
- Use minimum password length of 15 characters for administrator accounts.
- Use minimum password length of 8 characters for standard users.
- Require the use of alphanumeric passwords and symbols.
- Prevent the use of personal information as password such as phone numbers and dates of birth.