Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
PHP Security From The Inside
Federico Biancuzzi, 2007-02-05

Stefan Esser is the founder of both the Hardened-PHP Project and the PHP Security Response Team (which he recently left). Federico Biancuzzi discussed with him how the PHP Security Response Team works, why he resigned from it, what features he plans to add to his own hardening patch, the interaction between Apache and PHP, the upcoming "Month of PHP bugs" initiative, and common mistakes in the design of well-known applications such as WordPress.

Comments Mode:
PHP Security From The Inside 2007-02-05
Anonymous (1 replies)
PHP Security From The Inside 2007-02-07
PHP Application Dev. (3 replies)
Re: PHP Security From The Inside 2007-02-08
Anonymous
Re: PHP Security From The Inside 2007-02-15
Anonymous
Re: PHP Security From The Inside 2007-02-20
Don Hopkins
Blame others, hype yourself 2007-02-08
Sebs (2 replies)
Re: Blame others, hype yourself 2007-02-08
Anonymous (1 replies)
Re: Re: Blame others, hype yourself 2007-02-15
Anonymous (1 replies)
Re: Blame others, hype yourself 2007-02-13
Anonymous
PHP Security From The Inside 2007-02-20
brokenToy
This is highly irresponsible 2007-02-20
Paul Hickman (2 replies)
Re: This is highly irresponsible 2007-02-20
Mark Zein
Re: This is highly irresponsible 2007-02-20
John Carmichael (1 replies)
First off, bug reports don't fuel script kiddies, POC code does. By definition a script kiddie isn't going to have the requisite skills to do anything with a bug report. Plus let's not pretend that they don't have access to a huge list of unpatched bugs already from security mailing lists.

Stefan was apparently unable to convince the PHP devs to do anything when he was one of them so really this seems his only option. It shows his dedication to the language to continue to care and attempt to better it.

Sometimes the only way to get someone's attention is to shove their nose in their shit. Tends to get them to notice. MoAB seemed to get Apple off their security high horse and they patched some bugs they ignored before. I can only hope the PHP devs will have half the sense Apple did in how they respond to this.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/432/34374#34374
Re: Re: This is highly irresponsible 2007-02-21
Anonymous (1 replies)
PHP Security From The Inside 2007-08-13
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus