dragon0023 2013-03-27 21:54
浏览 32
已采纳

单个管理员网站的安全性? [关闭]

A couple weeks ago I decided to learn PHP and make a blog from scratch. Most of the features are completed so now I'm looking at security, specifically for the admin area. As it stands right now, in this admin area I will manage (database) content. I've been reading many articles regarding security, such as:

The definitive guide to form-based website authentication

http://www.wikihow.com/Create-a-Secure-Login-Script-in-PHP-and-MySQL

http://www.wikihow.com/Create-a-Secure-Session-Managment-System-in-PHP-and-MySQL

What are best practices for securing the admin section of a website?

Admin section for website - security?

securing my admin page that accesses several php files

and a bunch of Google articles regarding SSL

Basically, I'm just having trouble understanding exactly how much security I need with regards to the admin login page and the admin area. The consensus seems to be that I should use SSL, but that seems like overkill to me since this is a brand new website with initially 0 visitors.

In addition, I'm now starting to ask why I even need an admin area. If I'm the only person operating the blog, why couldn't I just manage the content from phpmyadmin? Without an admin area (and without requiring users to register to post comments) I shouldn't need SSL for anything. There wouldn't be any sharing of sensitive information. Wouldn't it make my life easier not to even have an admin section in this case?

So to clarify, I'm just trying to understand what the appropriate level of security protections would be for a brand new website with a single admin operating the website and if this website has an admin login page and an admin login area. Obviously I'll take measures to protect against SQL injections and brute force attacks, but what would be an appropriate measure to protect sensitive data such as an admin password? Thanks in advance for the help!

  • 写回答

1条回答 默认 最新

  • dqajyxqem115006813 2013-03-27 21:59
    关注

    Think of what kind of info you are going to protect with this security system. Next think of what you will lose if someone breaks through it. Put your time needed to write and implement really good security on the other hand. Ask yourself what is more important? That's all =)

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 WPF 大屏看板表格背景图片设置
  • ¥15 这个主板怎么能扩出一两个sata口
  • ¥15 不是,这到底错哪儿了😭
  • ¥15 2020长安杯与连接网探
  • ¥15 关于#matlab#的问题:在模糊控制器中选出线路信息,在simulink中根据线路信息生成速度时间目标曲线(初速度为20m/s,15秒后减为0的速度时间图像)我想问线路信息是什么
  • ¥15 banner广告展示设置多少时间不怎么会消耗用户价值
  • ¥16 mybatis的代理对象无法通过@Autowired装填
  • ¥15 可见光定位matlab仿真
  • ¥15 arduino 四自由度机械臂
  • ¥15 wordpress 产品图片 GIF 没法显示