Главная
Study mode:
on
1
Intro
2
What we already do
3
PHP
4
PHP Documentation
5
ThroughScene
6
Snuffleupagus
7
Babar
8
PHP eval
9
Disable function
10
Disable function call
11
Complex rules
12
Drop call to internalfunc
13
Filter unviable content
14
Code examples
15
PHP features
16
System function
17
Male
18
Roaming
19
Cookies
20
Documentation
21
Analyzing documentation
22
PHP special object
23
How we are killing it
24
XML external entities
25
Demos
26
Authentication bypass
27
Post variable
28
Remote code
29
Blacklisting
30
Deadening
31
Performance Impact
32
Sloppy Comparison
33
Release Party
34
PHP Energy
35
Reddit
Description:
Explore a conference talk on Snuffleupagus, an open-source PHP security module designed to address vulnerabilities in PHP 7 applications. Learn about its features for passively eliminating PHP-specific bug classes and implementing virtual-patching at the PHP level. Discover how this tool allows for precise, false-positive-free, and low-overhead vulnerability patching without modifying application code. Gain insights into PHP security, including topics such as disabling functions, filtering content, handling PHP eval, and addressing XML external entities. Understand the performance impact and benefits of using Snuffleupagus in secure web hosting environments.

Snuffleupagus - Killing Bugclasses in PHP 7, Virtual-Patching the Rest

Cooper
Add to list
0:00 / 0:00