WebApp Sec mailing list archives
Re: Ten Security Checks for PHP, Part 1
From: "Sverre H. Huseby" <shh () thathost com>
Date: Sat, 22 Mar 2003 21:41:19 +0100
[Michael Howard] | Aaarrrgggg... [...] | | This is just wrong. The security issue is NOT THESE FUNCTIONS - | it's the data, the fact that $page is untrusted is the issue.... Eh, from the "Ten Security Checks for PHP, Part 1", I can't see that anyone says that those functions are wrong. The functions are listed in the "what to look for" section. Anyone auditing a PHP program should "look for" those functions, and check that they do what is mentioned in the "Possible fixes or improvement" section. Sverre. -- shh () thathost com http://shh.thathost.com/
Current thread:
- Ten Security Checks for PHP, Part 1 Bob Auger (Mar 21)
- <Possible follow-ups>
- RE: Ten Security Checks for PHP, Part 1 Michael Howard (Mar 22)
- RE: RE: Ten Security Checks for PHP, Part 1 {Very usefull sugestions....} Ing. Bernardo Lopez (Mar 23)
- Re: Ten Security Checks for PHP, Part 1 Sverre H. Huseby (Mar 23)
- RE: Ten Security Checks for PHP, Part 1 Michael Howard (Mar 23)
