public marks

PUBLIC MARKS from mbertier with tags security & php

2007

Suhosin 0.9.21 - XSS Protection - PHP Security Blog

It has been a very long time since the last Suhosin extension has been released, but today this has changed with the release of Suhosin 0.9.21. Among the changes are two new features that will protect applications that put too much trust into the SERVER variables from several XSS (and SQL injection) attacks. These features are suhosin.server.strip and suhosin.server.encode.

PHPIDS » Web Application Security 2.0 » Index

by 1 other (via)
PHPIDS (PHP-Intrusion Detection System) is a simple to use, well structured, fast and state-of-the-art security layer for your PHP based web application. The IDS neither strips, sanitizes nor filters any malicious input, it simply recognizes when an attacker tries to break your site and reacts in exactly the way you want it to. Based on a set of approved and heavily tested filter rules any attack is given a numerical impact rating which makes it easy to decide what kind of action should follow the hacking attempt. This could range from simple logging to sending out an emergency mail to the development team, displaying a warning message for the attacker or even ending the user’s session.

2006

PHP Security Consortium: PHPSecInfo

by 8 others (via)
The idea behind PHPSecInfo is to provide an equivalent to the phpinfo() function that reports security information about the PHP environment, and offers suggestions for improvement. It is not a replacement for secure development techniques, and does not do any kind of code or app auditing, but can be a useful tool in a multilayered security approach.

Checklist for Securing PHP Configuration | Ayman Hourieh's Blog

by 3 others (via)
Inside is a check list of settings that are intended to harden the default PHP installation.

2005

Web Application Security Reviews | PHP Everywhere

by 2 others (via)
After a while, the requirements are pretty similar, but to pass our first audit wasn't easy. Here's a sampling of what is required

mbertier's TAGS related to tag security

advices +   apache +   audi +   audit +   bestpractices +   clevermarks +   database +   debian +   dev +   example +   firefox +   flash +   framework +   groupe:clever age +   hotlinked +   howto +   http +   introduction +   ipcop +   java +   linux +   microsoft +   mozilla +   mysql +   network +   openid +   php +   php5 +   pki +   ruby +   spam +   sql +   sso +   standards +   testcases +   tools +   usability +   web +   web services +   webdav +   webdev +   writing +   xss +