PHP security » Computer internet security  
Computer and internet security news
computer and networking security portal
 
|
|
|
News
|
Advertise
|
|
Products
|
Contact

‘PHP security’ News

Cross site scripting in php

Monday, December 24, 2007 6:32

The media has helped make cross-site scripting (XSS) a familiar term, and the attention is deserved. It is one of the most common security vulnerabilities in web applications, and many popular open source PHP applications suffer from constant XSS vulnerabilities. XSS attacks have the following characteristics: Exploit the trust a user has for a ...

This was posted under category: PHP security  |  Read Full Story  |  0 Comments

Cross site request forgeries in php

Monday, December 24, 2007 6:30

Despite the similarities in name, cross-site request forgeries (CSRF) are an almost opposite style of attack. Whereas XSS attacks exploit the trust a user has in a web site, CSRF attacks exploit the trust a web site has in a user. CSRF attacks are more dangerous, less popular (which means ...

This was posted under category: PHP security  |  Read Full Story  |  1 Comment

Chunk_split() Overflow not fixed at all…

Monday, June 4, 2007 15:07

If you are one of the guys that read the PHP CVS commits you usually know about the security bugs months before the rest of the community and this is no news for you. During the last 24h the following fix was merged into the PHP CVS. Corrected fix for CVE-2007-2872 This ...

This was posted under category: PHP security  |  Read Full Story  |  0 Comments
Tagged with:

Google for me and get Zend

Friday, June 1, 2007 10:21

Brought to you from one of the comments in my blog. Google for "Stefan Esser" and get a sponsored link for Zend. http://www.google.com/search?q=%22Stefan+Esser%22 Popularity: unranked [?]Read more at blog-admin@nopiracy.de (Stefan Esser)

This was posted under category: PHP security  |  Read Full Story  |  0 Comments
Tagged with:

PHP 5.2.3 released…

Friday, June 1, 2007 2:27

PHP 5.2.3 was released with several security fixes. Again not all security fixes are mentioned in the release announcement. Again security bugs known to the developers were not correctly fixed. More info here. PS: Why does PHP.net always release security fixes just before the weekend? PHP Releases have historically been packaged and tagged on Wednesday, ...

This was posted under category: PHP security  |  Read Full Story  |  0 Comments
Tagged with: ,

PHP 4 - Reference Counter Overflow Fix

Sunday, May 20, 2007 11:06

Because the PHP developers do not want to fix the PHP 4 Reference Counter Overflow Vulnerability that was disclosed during the Month of PHP Bugs the Hardened-PHP Project as usual had to step in to protect the users of PHP. I created a patch for the refcount overflow problem that took ...

This was posted under category: PHP security  |  Read Full Story  |  0 Comments
Tagged with:

Suhosin 0.9.20 and crypt() Thread Safety Vulnerability

Saturday, May 19, 2007 16:35

I just released Suhosin 0.9.20 that adds a few new features and bugfixes. The most important addition is that a mutex is placed around the call to the system’s crypt() function to ensure thread safety. This mutex is necessary to close a bunch of possible attacks on the libc crypt() ...

This was posted under category: PHP security  |  Read Full Story  |  0 Comments
Tagged with:

OWASP Risk Evaluation

Friday, May 11, 2007 10:00

When you read the OWASP risk evaluation standard carefully you might get as confused as I got. They estimate the risk by first estimating the likelihood and then estimating the technical and business impact. The estimation is done by assigning the numbers 0..9 to a number of factors. So far so ...

This was posted under category: PHP security  |  Read Full Story  |  0 Comments
Tagged with:





:::: Recent entries


 
Join My Community at MyBloglog!



My BlogCatalog BlogRank

Computers Blogs - Blog Top Sites