News Feed
Sections




News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

Rochak Chauhan's Blog:
Top Ten Security Vulnerabilities in PHP Code
August 04, 2008 @ 12:58:10

Rochak Chauhan has come up with a list of ten things, some security problems that could be lurking in your applications waiting to pop up at the worst time. Here's his list:

  • Unvalidated Parameters
  • Broken Access Control
  • Broken Account and Session Management
  • Cross-Site Scripting (XSS) Flaws
  • Buffer Overflows
  • Command Injection Flaws
  • Error Handling Problems
  • Insecure Use of Cryptography
  • Remote Administration Flaws
  • Web and Application Server Misconfiguration

Each item on the list has a bit of detail (and sometimes some code) to help point out the problem. Some of them even have references to external sources and packages to help you solve the problems.

0 comments voice your opinion now!
security vulnerabilities list example references


blog comments powered by Disqus

Similar Posts

Secunis.com: Travelsized CMS index.php Cross-Site Scripting Vulnerabilities

CodeSnipers.com: Interview with Chris Shiflett

Dan Scott's Blog: Serendipity (s9y) blog: Security release

Nick Halstead's Blog: Programming Tips #9 "debug_backtrace"

LoLoCoJr BLog: Rewriting a (large) PHP application to Rails, part 1


Community Events





Don't see your event here?
Let us know!


bugfix install list series language api opinion framework symfony voicesoftheelephpant community deployment interview podcast library laravel package introduction tips release

All content copyright, 2014 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework