I'm looking for a complete list of security guidelines for programming and deploying PHP web sites and applications on an Apache (Linux) server. Basically, a "security check list" to run through before finishing a project. I.e.,
- Cross Site Scripting
- Cross Site Request Forgery
- Sanitize form data that goes into database
- Disable register globals and error reporting in custom php.ini
- Upload files below web root ...(the list goes on)
I did some searching on the internet and in this forum, but couldn't find a comprehensive, succinct, and complete list of guidelines.
Thanks in advance.