Easy-to-follow video tutorials help you learn software, creative, and business skills.Become a member

Keeping versions up to date

From: Creating Secure PHP Websites

Video: Keeping versions up to date

The first step in securing your PHP installation

Keeping versions up to date

The first step in securing your PHP installation is keeping all of your versions up to date. Keeping versions up to date is quite simply both the easiest and the most important security measure that you can take. Keeping your site secure is going to require an ongoing commitment from you. You can't simply install all the software, launch the website, and then walk away and have it be secure. There are most likely bugs in the software that you're using, that you don't know about, that you can't know about. Those bugs will be discovered over time, either by the good guys or by the bad guys, and those bugs will get fixed.

That's why version updates matter so much. They include bug fixes and security patches that you need. And by the time these security issues get fixed, I guarantee that the bad guys know about them and are ready to use them against you if you haven't upgraded. Now, this applies not just to PHP, but also to other software that you're using for your installation, your web server, your database, libraries of code, and code from third parties, especially if you're using a framework or an application like WordPress. You should also make sure that all your servers are kept on the same latest versions of the software.

Of course, you should test new versions in development or in the staging server in order to catch problems before you put them into production, but as quickly as possible, you want to get all servers on the same version. It would be a real shame if you had a security issue in production that you didn't notice because your development server was running a newer version that had fixed the security issue. Having good software tests in place will also make upgrading versions much easier. It's also a good idea to look around you and to find email lists, RSS feeds or Twitter users that you can follow or subscribe to, which can help to clue you in when new versions become available.

Of course, to find out the latest version of PHP, the best place to look is php.net. On php.net, you can generally find the latest version by looking in the upper right-hand corner and you'll see the latest versions there available for download. There's also usually a list of the releases that come out right here on the home page and you can scroll down through those to find the latest version. I also want to point out that many times these updates include fixes that are referenced by a CVE number like this one. Those refer to the common vulnerabilities and exposures database, which you can find at cve.mitre.org.

If you were to search for that particular CVE that we were just looking at, you'll see that it will tell us what the vulnerability is. That's letting us know then that this version fixes that vulnerability. This was a security hold that has now been fixed by upgrading to this latest version. So you want to be on the lookout for those kinds of security updates in these upgrades. So before you do anything else to improve your security, do this one thing. Make it a regular habit to keep your PHP installation updated.

Show transcript

This video is part of

Image for Creating Secure PHP Websites
Creating Secure PHP Websites

41 video lessons · 3750 viewers

Kevin Skoglund
Author

 

Start learning today

Get unlimited access to all courses for just $25/month.

Become a member
Sometimes @lynda teaches me how to use a program and sometimes Lynda.com changes my life forever. @JosefShutter
@lynda lynda.com is an absolute life saver when it comes to learning todays software. Definitely recommend it! #higherlearning @Michael_Caraway
@lynda The best thing online! Your database of courses is great! To the mark and very helpful. Thanks! @ru22more
Got to create something yesterday I never thought I could do. #thanks @lynda @Ngventurella
I really do love @lynda as a learning platform. Never stop learning and developing, it’s probably our greatest gift as a species! @soundslikedavid
@lynda just subscribed to lynda.com all I can say its brilliant join now trust me @ButchSamurai
@lynda is an awesome resource. The membership is priceless if you take advantage of it. @diabetic_techie
One of the best decision I made this year. Buy a 1yr subscription to @lynda @cybercaptive
guys lynda.com (@lynda) is the best. So far I’ve learned Java, principles of OO programming, and now learning about MS project @lucasmitchell
Signed back up to @lynda dot com. I’ve missed it!! Proper geeking out right now! #timetolearn #geek @JayGodbold
Share a link to this course

What are exercise files?

Exercise files are the same files the author uses in the course. Save time by downloading the author's files instead of setting up your own files, and learn by following along with the instructor.

Can I take this course without the exercise files?

Yes! If you decide you would like the exercise files later, you can upgrade to a premium account any time.

Become a member Download sample files See plans and pricing

Please wait... please wait ...
Upgrade to get access to exercise files.

Exercise files video

How to use exercise files.

Learn by watching, listening, and doing, Exercise files are the same files the author uses in the course, so you can download them and follow along Premium memberships include access to all exercise files in the library.


Exercise files

Exercise files video

How to use exercise files.

For additional information on downloading and using exercise files, watch our instructional video or read the instructions in the FAQ .

This course includes free exercise files, so you can practice while you watch the course. To access all the exercise files in our library, become a Premium Member.

Are you sure you want to mark all the videos in this course as unwatched?

This will not affect your course history, your reports, or your certificates of completion for this course.


Mark all as unwatched Cancel

Congratulations

You have completed Creating Secure PHP Websites.

Return to your organization's learning portal to continue training, or close this page.


OK
Become a member to add this course to a playlist

Join today and get unlimited access to the entire library of video courses—and create as many playlists as you like.

Get started

Already a member ?

Become a member to like this course.

Join today and get unlimited access to the entire library of video courses.

Get started

Already a member?

Exercise files

Learn by watching, listening, and doing! Exercise files are the same files the author uses in the course, so you can download them and follow along. Exercise files are available with all Premium memberships. Learn more

Get started

Already a Premium member?

Exercise files video

How to use exercise files.

Ask a question

Thanks for contacting us.
You’ll hear from our Customer Service team within 24 hours.

Please enter the text shown below:

The classic layout automatically defaults to the latest Flash Player.

To choose a different player, hold the cursor over your name at the top right of any lynda.com page and choose Site preferences from the dropdown menu.

Continue to classic layout Stay on new layout
Exercise files

Access exercise files from a button right under the course name.

Mark videos as unwatched

Remove icons showing you already watched videos if you want to start over.

Control your viewing experience

Make the video wide, narrow, full-screen, or pop the player out of the page into its own window.

Interactive transcripts

Click on text in the transcript to jump to that spot in the video. As the video plays, the relevant spot in the transcript will be highlighted.

Thanks for signing up.

We’ll send you a confirmation email shortly.


Sign up and receive emails about lynda.com and our online training library:

Here’s our privacy policy with more details about how we handle your information.

Keep up with news, tips, and latest courses with emails from lynda.com.

Sign up and receive emails about lynda.com and our online training library:

Here’s our privacy policy with more details about how we handle your information.

   
submit Lightbox submit clicked
Terms and conditions of use

We've updated our terms and conditions (now called terms of service).Go
Review and accept our updated terms of service.