SecurityPHP related security News State of the Art Post Exploitation in Hardened PHP EnvironmentsLast updated on Sun, 11/08/2009 - 09:15
In this paper, Stefan Esser discuss the different protections an attacker faces in hardened PHP environments, after succeeded in executing arbitrary PHP code. He introduce new techniques to overcome most of them by the use of local PHP exploits. He demonstrate how info leak and memory corruption vulnerabilities can be combined to enable PHP applications to read and write arbitrary memory. He will show step by step how important memory structures can be leaked and manipulated in order to deactivate or overcome protections. New PHP Interpreter Finds XSS, Injection HolesLast updated on Sat, 06/20/2009 - 02:28
A group of researchers from MIT, Stanford, and Syracuse has developed a new program, named 'Ardilla,' which can analyze PHP code for cross-site scripting (XSS) and SQL injection attack vulnerabilities. SANS Compiles Top 25 Most Dangerous Programming ErrorsLast updated on Tue, 01/13/2009 - 14:31
Experts from more than 30 US and international cyber security organizations jointly released the consensus list of the 25 most dangerous programming errors that lead to security bugs and that enable cyber espionage and cyber crime. Shockingly, most of these errors are not well understood by programmers; their avoidance is not widely taught by computer science programs; and their presence is frequently not tested by organizations developing software for sale. The impact of these errors is far reaching. PHP 5.2.7 removed from distribution over security bugLast updated on Wed, 12/10/2008 - 19:01
PHP version 5.2.7 has been removed from distribution because of a security issue that affects certain configurations. According to a notice from the Apache-backed project, PHP users should use version 5.26 until PHP 5.2.8 is released with a fix for this issue. |
Active forum topics
Current jobs
No job postings to display
Who's new
Poll
|
