Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: PHP as a secure language? PHP worms? [was: Re: new linux malware] |
|---|---|
| Date: | Wed, 22 Feb 2006 21:48:55 +1100 |
This one time, at band camp, Gadi Evron <ge@linuxbox.org> wrote:
3. Staying on top of new PHP vulnerabilities has become impossible, popping around everywhere.
What vulnerabilities in PHP? Are implying the fault is within the language itself? This is akin to saying C has vulnerabilites because some script kiddie wrote a poor application.
4. Determining how secure a PHP application is, looking at the code and for how silly past vulnerabilities were (i.e. looking at the coder rather than the code) is now more important than the actual application.
As with all web based technologies, security should be the foundation of the application
Much like their self criticism said, PHP needs to grow to a far more secure language, much like we need to chose more carefully what PHP software we use.
Which self critism is this?
Some of us have been joking for a while about creating a script to choose from different paragraph we create, and email bugtraq re-assembling the randomly with a new PHP bug and a random PHP application name every few hours. Would any of us be able to readily tell the difference?
Perhaps we can do the same for linux kernel problems and blame it on C? Kind regards Kevin -- "Democracy is two wolves and a lamb voting on what to have for lunch. Liberty is a well-armed lamb contesting the vote."
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] SSH bypassing in Phishing, Gadi Evron |
|---|---|
| Next by Date: | [Full-disclosure] iDefense Security Advisory 02.24.06: SCO Unixware Setuid ptrace Local Privilege Escalation Vulnerability, labs-no-reply |
| Previous by Thread: | Re: PHP as a secure language? PHP worms? [was: Re: new linux malware], Thomas M. Payerle |
| Next by Thread: | Re: PHP as a secure language? PHP worms? [was: Re: new linux malware], Jamie Riden |
| Indexes: | [Date] [Thread] [Top] [All Lists] |