News Feed
Sections
News Archive


Community Events
php|tek 2008 PHP Conference



feed this:

GNUCitizen.org:
Reviewing Practical PHP Exploitation Techniques
0 comments :: posted Friday April 04, 2008 @ 12:09:22
voice your opinion now!

From the GNUCitizen blog, there's a new post about a recent meeting (of the OWASP London Chapter) where several presentations were given on methods for exploiting PHP applications. The three talks given were:

  • Rodrigo Marcos - hacking PHP sockets for fun and profit
  • David Kierznowski - exploitation techniques using real world examples
  • Colin Watson - talk about security badges

There's links to the slides for one the formal presentations, the exploitation techniques - two sets: the remote exploit examples and local exploit examples.

tagged with: practical exploit example talk slides owasp


Builder.com.au:
PHP exploit code plants itself in GIF
0 comments :: posted Friday June 22, 2007 @ 12:41:00
voice your opinion now!

Builder.com.au has a new article today about the recent image issue - the PHP code embedded inside the GIF - that's come up on several sites.

The exploit code slipped through the site's defenses with the aid of a legitimate image at the beginning of the file, according to a blog post on the Sans Institutes's Internet Storm Center. [...] Malicious attackers planted PHP coded exploit script within an image file. PHP is often used as a programming language to create dynamic Web sites.

The article reports that, while this exploit hasn't happened much, the occurrences of it's use are growing with victims in a wide range of classifications - from small personal sites out to a certain major image hosting site. This same issue was discussed here on the PHPClasses.org website as well.

tagged with: gif exploit image script embed gif exploit image script embed


book cakephp application package security framework ajax developer pecl mysql releases database code conference PEAR release zend job PHP5 zendframework

All content copyright, 2008 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework