Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Vuln-Dev
[Top] [All Lists]

Re: PHP as a secure language? PHP worms? [was: Re: new linux malware]

Subject: Re: PHP as a secure language? PHP worms? [was: Re: new linux malware]
Date: Sat, 25 Feb 2006 10:07:52 +1300
On 22/02/06, Kevin Waterson <kevin@oceania.net> wrote:
This one time, at band camp, Gadi Evron <ge@linuxbox.org> wrote:

3. Staying on top of new PHP vulnerabilities has become impossible,
popping around everywhere.

What vulnerabilities in PHP?
Are implying the fault is within the language itself?

I think Gadi meant vulnerabilities in PHP applications; though the
language doesn't make it particularly easy to write secure code.

This is akin to saying C has vulnerabilites because some script kiddie
wrote a poor application.

Like this ?

"We can give you advice on how to write good cryptographic code. Avoid
any programming language that allows buffer overflows. Specifically:
don't use C or C++" -- Practical Cryptography, Schneier and Ferguson,
(p149 in my copy).

It's a point of view that has something to be said for it. You *can*
write secure code in C and PHP, but it takes a lot of care and most
programmers don't take that care. I've been told privately that one
penetration tester could gain system privileges on the majority of
webservers he checked; that used to surprise me, but doesn't any
longer. I don't whether that's a 'vulnerability', 'disadvantage' or
'feature' of PHP and other scripting languages.

cheers,
 Jamie
--
Jamie Riden / jamesr@europe.com / jamie.riden@gmail.com

<Prev in Thread] Current Thread [Next in Thread>