News Feed
Jobs Feed
Sections

Recent Jobs

News Archive
ThinkPHP Blog:
Leveraging Security to PHP (using sausages)
March 10, 2006 @ 07:22:30

When do PHP security and sausages come together? Only in this post from the ThinkPHP blog that takes a look at their security application being developed specifically for finding issues with web applications - Chorizo.

Let's be honest - the guys over at bugtraq, full-disclosure and others make fun of us PHP people. Chorizo ScreenshotNot only do we provide the dramatis personae - be it phpBB, the Nuke family or XMLRPC, we also deliver remote code execution, XSS or SQL injections right to the security peoples' doorstep. Why does this happen? Are we all dumbnuts? That's not the explanation - at least not all of it.

In the history of PHP, users and ISPs have always been nice and friendly like our grandma. Their continued support even in rough times ensures PHP's ongoing success, so we shouldn't let them down and ignore everything they say (like we do with our grandmas).

Enter Chorizo, an easy-to-use, speedy little proxying bit of software that looks at the data coming through and finds whatever issues it can. It looks at where "web applications get interactive" instead of just spidering the sites, and checks multiple kinds of attacks including: XSS, SQL injections, code inclusions, code executions, HTTP response splitting, and many more. It's not open to the public just yet, but you can preregister to have an active account just as soon as it goes live.

0 comments voice your opinion now!
php security sausage web application vulnerabilities php security sausage web application vulnerabilities



Similar Posts

PHPit.net: Having fun with PHP\'s output buffer

Community News: The PHOCOA PHP Framework

Secunia.com: PHP "glob()" Code Execution Vulnerability

Pádraic Brady's Blog: RESTful Web Services with Zend Framework

Java World: BEA showing PHP on Java app server


Community Events









Don't see your event here?
Let us know!


job zendframework conference cakephp book application zend PHP5 example releases ajax security mysql release framework code database package PEAR developer

All content copyright, 2008 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework