Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
PHP Security From The Inside
Federico Biancuzzi, 2007-02-05

Stefan Esser is the founder of both the Hardened-PHP Project and the PHP Security Response Team (which he recently left). Federico Biancuzzi discussed with him how the PHP Security Response Team works, why he resigned from it, what features he plans to add to his own hardening patch, the interaction between Apache and PHP, the upcoming "Month of PHP bugs" initiative, and common mistakes in the design of well-known applications such as WordPress.

Comments Mode:
PHP Security From The Inside 2007-02-05
Anonymous (1 replies)
PHP Security From The Inside 2007-02-07
PHP Application Dev. (3 replies)
Re: PHP Security From The Inside 2007-02-08
Anonymous
Re: PHP Security From The Inside 2007-02-15
Anonymous
Re: PHP Security From The Inside 2007-02-20
Don Hopkins
Blame others, hype yourself 2007-02-08
Sebs (2 replies)
Re: Blame others, hype yourself 2007-02-08
Anonymous (1 replies)
Re: Re: Blame others, hype yourself 2007-02-15
Anonymous (1 replies)
Re: Blame others, hype yourself 2007-02-13
Anonymous
PHP Security From The Inside 2007-02-20
brokenToy
This is highly irresponsible 2007-02-20
Paul Hickman (2 replies)
Re: This is highly irresponsible 2007-02-20
Mark Zein
Are you aware that security bugs disclosed to the PHP developers are usually fixed and then wait in the CVS for several months until they make it into a bugfix release (that most probably breaks tons of sites like PHP 5.2.1 successfully demonstrated)?

Are you really that ignorant to believe that not every single fixed security hole in the PHP CVS is immediately triggering some skript kiddy that watches the CVS mailinglist?

By disclosing the security holes the public atleast knows about them.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/432/34370#34370
Re: This is highly irresponsible 2007-02-20
John Carmichael (1 replies)
Re: Re: This is highly irresponsible 2007-02-21
Anonymous (1 replies)
PHP Security From The Inside 2007-08-13
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus