<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Fri, 24 May 2013 07:47:48 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[Zend Developer Zone: Security Tip #21 (Subscribe to BugTraq)]]></title>
      <guid>http://www.phpdeveloper.org/news/7554</guid>
      <link>http://www.phpdeveloper.org/news/7554</link>
      <description><![CDATA[<p>
The latest Security Tip has <a href="http://devzone.zend.com/node/view/id/1882">been posted</a> on the Zend Developer Zone about the importance of the SecurityFocus newsletter.
</p>
<blockquote>
Today's PHP security tip is short, sweet and easily actionable. It fits in well with the theme of the last one, to stay vigilant. Here's another resource for you to consider: If you are not already subscribed, you should subscribe to the Security Focus newsletter.
</blockquote>
<p>
He <a href="http://www.securityfocus.com/archive">links to</a> their signup page and points out the most useful of their offerings - the BugTraq list.
</p>
<blockquote>
BugTraq is a full disclosure moderated mailing list for the detailed discussion and announcement of computer security vulnerabilities: what they are, how to exploit them, and how to fix them.
</blockquote>]]></description>
      <pubDate>Tue, 03 Apr 2007 11:20:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[SecurityFocus.com: PHP Security From The Inside (Interview with Stefan Esser)]]></title>
      <guid>http://www.phpdeveloper.org/news/7239</guid>
      <link>http://www.phpdeveloper.org/news/7239</link>
      <description><![CDATA[<p>
Over on the SecurityFocus website, there's <a href="http://www.securityfocus.com/columnists/432">an interview</a> posted with <i>Stefan Esser</i> of the Hardened-PHP Project (as interviewed by <i>Federico Biancuzzi</i>.
</p>
<blockquote>
Federico Biancuzzi discussed with him how the PHP Security Response Team works, why he resigned from it, what features he plans to add to his own hardening patch, the interaction between Apache and PHP, the upcoming "Month of PHP bugs" initiative, and common mistakes in the design of well-known applications such as WordPress.
</blockquote>
<p>
Some of the topics <a href="http://www.securityfocus.com/columnists/432">discussed</a> include
<ul>
<li>the Hardened-PHP Project
<li>Suhosin
<li>the PHP Security Response Team (his role in it and why he left)
<li>PHP5's security focus versus PHP4's
<li>and more...
</ul>
Check out <a href="http://www.securityfocus.com/columnists/432/">the full interview</a> to have all of your questions answered.
</p>]]></description>
      <pubDate>Wed, 07 Feb 2007 11:36:00 -0600</pubDate>
    </item>
    <item>
      <title><![CDATA[PHP Security Consortium: SecurityFocus Newsletter #361]]></title>
      <guid>http://www.phpdeveloper.org/news/5968</guid>
      <link>http://www.phpdeveloper.org/news/5968</link>
      <description><![CDATA[<p>
The latest SecurityFocus Summary has been posted on the PHP Security Consortium site today, <a href="http://phpsec.org/projects/vulnerabilities/securityfocus361.html">Issue #361</a>.
</p>
<p>
Included in this issue are vulnerabilities for:
<ul>
<li><a href="http://www.securityfocus.com/bid/19217">SecurityImages Component Multiple Remote File Include Vulnerabilities</a>
<li><a href="http://www.securityfocus.com/bid/19238">Ajax Chat Multiple Remote Vulnerabilities</a>
<li><a href="http://www.securityfocus.com/bid/19232">ATutor Multiple SQL Injection Vulnerabilities</a>
<li><a href="http://www.securityfocus.com/bid/19219">Coppermine Photo Gallery Theme.PHP Remote File Include Vulnerability</a>
<li><a href="http://www.securityfocus.com/bid/19254">PHPAuction PHPAds_Path Variable Remote File Include Vulnerability</a>
<li><a href="http://www.securityfocus.com/bid/19246">myEvent Myevent.PHP Remote File Include Vulnerability</a>
</ul>
</p>
<p>
This is just a sampling of the issues reported, so head over to <a href="http://phpsec.org/projects/vulnerabilities/securityfocus361.html">the full listing</a> for the complete information.
</p>]]></description>
      <pubDate>Mon, 07 Aug 2006 06:37:07 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[PHP Security Consortium: SecurityFocus Newsletter #345]]></title>
      <guid>http://www.phpdeveloper.org/news/5185</guid>
      <link>http://www.phpdeveloper.org/news/5185</link>
      <description><![CDATA[The <a href="http://www.phpsec.org</a>PHP Security Consortium</a> has posted their latest <a href="http://phpsec.org/projects/vulnerabilities/securityfocus.html">SecurityFocus summary</a> on their site today for April 11th, 2006.
<p>
Software mentioned in <a href="http://phpsec.org/projects/vulnerabilities/securityfocus345.html">this edition</a> includes:
<ul>
<li>PHPWebGallery
<li>JetPhoto
<li>PHPList
<li>ShopWeezle
<li>XBrite
<li>PHPKIT
</ul>
<p>
There are several more <a href="http://phpsec.org/projects/vulnerabilities/securityfocus345.html">mentioned</a> besides those above, so be sure to check out the full report to see if any scripts you use are effected.]]></description>
      <pubDate>Mon, 17 Apr 2006 07:05:21 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[PHP Security Consortium: New SecurityFocus Summaries Posted (#333, #334, #340, #341)]]></title>
      <guid>http://www.phpdeveloper.org/news/5055</guid>
      <link>http://www.phpdeveloper.org/news/5055</link>
      <description><![CDATA[The <a href="http://www.phpsec.org">PHP Security Consortium</a> has posted four new SecurityFocus Summaries today.
<p>
<ul>
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus341.html">Issue #341</a> - including issues for WordPress, DSCounter/DSNewsletter/DSPoll PollID, and MyBB
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus342.html">Issue #342</a> - including issues for PHPMyAdmin, SoftBB, CutePHP, and PHPWebSite
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus334.html">Issue #334</a> - including issues for Noah's Classifieds, VBulletin, and PEHEPE Membership Management System
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus334.html">Issue #340</a> - including issues for Navboard, PHPChamber, MyPhPim, and PHPNuke
</ul>
<p>
As always, the latest issues are available from <a href="http://phpsec.org/projects/vulnerabilities/securityfocus.html">the Consortium's website</a> under the Projects > SecurityFocus Summaries portion of the site. Check out the latest so you and your applications are protected.]]></description>
      <pubDate>Mon, 27 Mar 2006 08:41:27 -0600</pubDate>
    </item>
    <item>
      <title><![CDATA[PHP Security Consortium: SecurityFocus Summaries Posted]]></title>
      <guid>http://www.phpdeveloper.org/news/4993</guid>
      <link>http://www.phpdeveloper.org/news/4993</link>
      <description><![CDATA[The <a href="http://www.phpsec.org">PHP Security Consortium</a> has posted several <a href="http://phpsec.org/projects/vulnerabilities/securityfocus.html">SecurityFocus summaries</a> on its site today dealing with a variety of applications and issues:
<p>
<ul>
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus340.html">Issue #340</a> - including apps like VBilletin, Noah's Classifieds, VBZoom, and Limbo
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus339.html">Issue #339</a> - including apps like PHP-Nuke, PHPWebSite, PEAR::Archive_Tar, and Mambo
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus338.html">Issue #338</a> - including apps like SquirrelMail, ADOdb, PostNuke, and MyBB
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus337.html">Issue #337</a> - including apps like PHP Event Calendar, RunCMS, Invision Power Board, and PHPNuke
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus336.html">Issue #336</a>
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus335.html">Issue #335</a>
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus332.html">Issue #332</a>
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus331.html">Issue #331</a>
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus330.html">Issue #330</a>
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus329.html">Issue #329</a>
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus328.html">Issue #328</a>
</ul>
<p>
The lists presented here are by no means comprehensive, so please check out the latest <a href="http://phpsec.org/projects/vulnerabilities/securityfocus.html">SecurityFocus summaries</a> for a complete listing of all affected applications.]]></description>
      <pubDate>Wed, 15 Mar 2006 07:05:59 -0600</pubDate>
    </item>
    <item>
      <title><![CDATA[PHP Security Consortium: SecurityFocus Summaries Posted]]></title>
      <guid>http://www.phpdeveloper.org/news/4803</guid>
      <link>http://www.phpdeveloper.org/news/4803</link>
      <description><![CDATA[The <a href="http://www.phpsec.org">PHP Security Consortium</a> has posted more SecurityFocus Summaries on their site today:
<ul>
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus327.html">#327</a> - includes issues with Drupal, PHPWordPress, WebCalendar, and KBase Express
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus328.html">#328</a> - includes issues with PHPMyAdmin, Web4Future, PHPForumPro, and MyBB
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus333.html">#333</a> - includes issues with Venom Board, Andromeda, MyPhPim, and PHP Toolkit 
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus334.html">#334</a> - includes issues with GeoBlog, microBlog, AOblogger, and My Amazon Store
</ul>
<p>
Of course, there are many, many more issues in each of these items than are psoted here, so be sure to <a href="http://phpsec.org/projects/vulnerabilities/securityfocus.html">check out</a]]></description>
      <pubDate>Mon, 06 Feb 2006 07:38:04 -0600</pubDate>
    </item>
    <item>
      <title><![CDATA[PHP Security Consortium: SecurityFocus Summaries Posted]]></title>
      <guid>http://www.phpdeveloper.org/news/4742</guid>
      <link>http://www.phpdeveloper.org/news/4742</link>
      <description><![CDATA[The <a href="http://www.phpsec.org">PHP Security Consortium</a> has posted several SecurityFocus Newsletters on their site today, including:
<ul>
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus332.html">#332</a> including apps like Chimera Web Portal, Drupal, TheWebForum, and Navboard
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus331.html">#331</a> including apps like SimpBook Guestbook, PHPSurveyor, PHPDocumentor, and PHPBB
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus330.html">#330</a> including apps like PHP Fusebox, Esselbach, ContentServ, and AbleDesign
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus329.html">#329</a> including apps like Flatnuke, Horde Mnemo, Arab Portal, PHPWebGallery and PHPNuke
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus327.html">#327</a> including apps like Drupal, PHPGreetz, PHPWordPress, PHP Web Statistik, and WebCalendar
</ul>
</quote>
<p>
As always, this list is by far not complete, so be sure to <a href="http://phpsec.org/projects/vulnerabilities/securityfocus.html">check out the current summaries</a> on the PHP Security Consortium site for the latest...
</ul>]]></description>
      <pubDate>Fri, 27 Jan 2006 07:19:18 -0600</pubDate>
    </item>
    <item>
      <title><![CDATA[PHP Security Consortium: SecurityFocus Newsletters Posted (#328, #327, #320, #319)]]></title>
      <guid>http://www.phpdeveloper.org/news/4553</guid>
      <link>http://www.phpdeveloper.org/news/4553</link>
      <description><![CDATA[The <a href="http://www.phpsec.org">PHP Security Consortium</a> has published more SecurityFocus Newsletters today:
<ul>
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus320.html">#320</a> - issues with phpMyAdmin, PHPWebSite, Complete PHP Counter, and Zeroblog
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus319.html">#319</a> - issues with PHP-Fusion, MyBloggie, OSCommerce, and Utopia News
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus327.html">#327</a> - issues with Drupal, PHPGreetz, PHPWordPress, NiceCoder iDesk, WebCalendar, and PHPAlbum (large list)
<li><a href="http://phpsec.org/projects/vulnerabilities/securityfocus328.html">#328</a> - issues with phpMyAdmin, Web4Future, PHPForumPro, Cars Portal Index, and MyBB
</ul>
<p>
As always, the items mentioned above are only a small taste of the contents of <a href="http://phpsec.org/projects/vulnerabilities/securityfocus.html">the newsletters</a>, so be sure to check them out <a href="http://phpsec.org/projects/vulnerabilities/securityfocus.html">in full</a> to see if one of your applications is listed...]]></description>
      <pubDate>Fri, 23 Dec 2005 07:50:55 -0600</pubDate>
    </item>
    <item>
      <title><![CDATA[PHP Security Consortium: SecurityFocus Newsletter #325 Posted]]></title>
      <guid>http://www.phpdeveloper.org/news/4391</guid>
      <link>http://www.phpdeveloper.org/news/4391</link>
      <description><![CDATA[The <a href="http://www.phpsec.org">PHP Security Consortium</a> has posted thier latest SecurityFocus summary today - <a href="http://phpsec.org/projects/vulnerabilities/securityfocus325.html">Issue #325</a>.
<p>
PHP Applications covered in <a href="http://phpsec.org/projects/vulnerabilities/securityfocus325.html">this issue</a> include: Horde, PHPNuke, Cyphor Show.PHP, PHPWCMS, Mambo, PHP Easy Download, Interspire ArticleLive NX, PHP-Fusion, and PHPMyFAQ. 
<p>
Of course, there are tons more that aren't listed here, so be sure to <a href="http://phpsec.org/projects/vulnerabilities/securityfocus325.html">head over</a> and check it out to be sure you and your applications are all safe...]]></description>
      <pubDate>Mon, 28 Nov 2005 06:26:42 -0600</pubDate>
    </item>
  </channel>
</rss>
