<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Sun, 06 Jul 2008 17:11:32 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[GNUCitizen.org: Reviewing Practical PHP Exploitation Techniques]]></title>
      <guid>http://www.phpdeveloper.org/news/9915</guid>
      <link>http://www.phpdeveloper.org/news/9915</link>
      <description><![CDATA[<p>
From the GNUCitizen blog, there's <a href="http://www.gnucitizen.org/blog/reviewing-practical-php-exploitation-techniques/">a new post</a> about a recent meeting (of the OWASP London Chapter) where several presentations were given on methods for exploiting PHP applications. The three talks given were:
</p>
<ul>
<li><i>Rodrigo Marcos</i> - hacking PHP sockets for fun and profit
<li><i>David Kierznowski</i> - exploitation techniques using real world examples
<li><i>Colin Watson</i> - talk about security badges
</ul>
<p>
There's links to the slides for one the formal presentations, the exploitation techniques - two sets: the <a href="http://www.withdk.com/archives/PHP%20Code%20Analysis-%20Real%20World%20Examples.pdf">remote exploit examples</a> and <a href="http://www.gnucitizen.org/blog/reviewing-practical-php-exploitation-techniques/PHP%20Code%20Analysis%20-%20Real%20World%20Examples.pdf">local exploit examples</a>.
</p>]]></description>
      <pubDate>Fri, 04 Apr 2008 12:09:22 -0500</pubDate>
    </item>
  </channel>
</rss>
