"clean" as variable name, preventing
client-side scripting
     cookies accessible with
     hashing password with
code injection
command injection 2nd
complexity, avoiding
constants, trustworthiness of data in
Cookie request header
     data sent in
     providing access to resources
     specification for
     storing username and password in
     theft of
credit card numbers, storing
critical actions, authentication before
cross-site request forgery (CSRF)
cross-site scripting (XSS)
     cookie theft and 2nd
     remote files and
     source of
     credit card numbers
     data in database
     mcrypt extension for
     resources for
     role of, in securing applications
     session data
     types of
CSRF (cross-site request forgery)

