Главная
Study mode:
on
1
Intro
2
Welcome!
3
What we are going to talk about today...
4
for example
5
Some things to avoid...
6
String Escaping
7
Correct way to escape
8
Input Cleaning
9
Random cool IE hack...
10
More Strings!!!!
11
Affected Functions?
12
Securing around PHP
13
Case Study
14
Target & Discovery
15
Step 2: Exploit!
16
Find the password!
17
Some easy ways this could have been avoided
18
Wrapping up...
Description:
Explore the dark side of PHP in this 35-minute conference talk from PHP UK Conference 2013. Delve into the language's troubled upbringing and potential security pitfalls. Learn about PHP's evolution, best development practices, and security considerations when working with C libraries. Discover unexpected function behaviors, browser quirks, and LAMP stack security configurations. Identify common mistakes, security antipatterns, and fallacies. Gain insights on code review techniques and developing a security-focused mindset. Cover topics such as string escaping, input cleaning, and securing PHP applications. Examine a real-world case study demonstrating target discovery and exploitation. Walk away with practical knowledge on defensive programming and strategies to mitigate PHP's potential vulnerabilities.

PHP is Evil - Defensive Programming

PHP UK Conference
Add to list