bloggallerycontact

Topics

Guide to PHP Security, small book review

I ordered Ilia Alshanetsky book - php|architect's Guide to PHP Security - about a month ago. I did so because php|architect said there would be books with Ilia's signature for the first ones being ordered. I thought it would be nice to have one, for the fun and because I enjoyed Ilia's speaks at the International PHP conferences (in Amsterdam).

Anyway, I received the book without the signature so I was a bit disappointed. I thought I misunderstood the ad. I did not really ordered the book for its content because I thought, with 6 years of PHP programming, I now knew enough about PHP security and stuff like that. I admit my first web applications really sucked in this matter, but now I think they should be ok.

As I take the underground everyday, I sometimes find myself without anything to read and having nothing to read in Paris underground is pretty boring, so I picked up Ilia's book for the ride.

Now that I reached the middle of the book (took me approx. 8 underground rides), I can say it's very good and I have discovered many ways to further improve my applications. I learned something new about PHP on almost every page. This book is not exactly for newbies, it sometimes goes into PHP internals and give you excellent tricks on how to improve both your scripts security and performance. The code examples are very short and illustrative. This makes the book very easy and fast to read.

Ilia definitely knows what he writes about and goes well beyond security by also giving you useful tricks on PHP performance and how PHP works internally.

The only thing I thought was missing is a chapter about backup strategies, because if your server gets compromised, the only recourse you'll have in most cases are your backups. It would be nice to have this as a free chapter :)

The good thing is that today (only), php|architect is making a special offer on the book.

Comments (3)  Permalink

Comments

Aaron Wormus @ 07.01.2006 17:10 CEST
I quickly ordered the book but didn't get a signed copy either... they must have gone quickly.
Richard Thomas @ 07.01.2006 18:42 CEST
I ordered the day it came out and got 2 seperate copies almost a week apart.. One with and one without sig..


Shrug.
Sean Coates @ 08.01.2006 02:37 CEST
I saw the stack of books that Ilia signed. We sold a large number of them at php|works in Toronto, and there were also substantial pre-orders.

Sorry you guys didn't get the autographed copies, but they DO exist, and I'm sure Ilia would be willing to sign your copies, if you manage to track him down (perhaps at php|tek? *plug**plug*). (-:

S

Add a comment

The Trackback URL to this comment is:
http://golgote.freeflux.net/blog/plugin=trackback(69).xml

No new comments allowed (anymore) on this post.