As a last minute addition to the Month of PHP Security we present an article by Ben Fuhrmannek about virtual meta-scripting bytecode for PHP and JavaScript.
(more…)
‘Articles & Tools’
Article: Virtual Meta-Scripting Bytecode for PHP and JavaScript
MOPS Submission 10: How to manage a PHP application’s users and passwords
It is time to present you the tenth and last external MOPS submission. It is an article by Solar Designer describing in length how to manage PHP application’s users and passwords.
(more…)
MOPS Submission 09: RIPS – A static source code analyser for vulnerabilities in PHP scripts
During the last hours of the CFP we received the following MOPS submission by Johannes Dahse. It is a static code analysing tool for PHP based on the tokenizer extension.
(more…)
MOPS Submission 08: Configuration Encryption Patch for Suhosin
Today it is time to present you the eighth external MOPS submission. It is an article by Juergen Pabel describing a new feature for the Suhosin Extension that allows encrypting configuration strings.
(more…)
MOPS Submission 07: Our Dynamic PHP – Obvious and not so obvious PHP code injection and evaluation
Today we want to present you the seventh external MOPS submission. It is an article about usual and unusual PHP code execution vulnerabilities sent in by Arthur Gerkis.
(more…)
MOPS Submission 06: Variable Initialization in PHP
Today we want to present you the sixth external MOPS submission. It is the second article sent in by Jakub Vrana. This one is about variable initialization in PHP.
(more…)
Article: Decoding a User Space Encoded PHP Script
Today we present you a short article about how to decode a PHP file encoded with the php-crypt.com PHP encoder. This article was written today by Stefan Esser after having seen an advertisement for php-crypt in the Xing PHP Development Forum.
(more…)
MOPS Submission 05 – The Minerva PHP Fuzzer
MOPS Submission 04 – Generating Unpredictable Session IDs and Hashes
Today we want to present you the fourth external MOPS submission. It was submitted by Jordi Boggiano and explains how to generate unpredictable session ids and hashes in PHP.
(more…)
MOPS Submission 03 – sqlite_single_query(), sqlite_array_query() Uninitialized Memory Usage
Today we want to present you the third external MOPS submission. It is the first of two submissions sent in by Mateusz Kocielski. This one is a detailed explanation about how to exploit the sqlite_single_query() and sqlite_array_query() uninitialized memory usage.
(more…)







