Professional PHP

PHP Programming, Web Development, PHP Advocacy and PHP Best Practices.
« PHP first impressions from a J2EE programmer
Flawed Microbenchmarks »

PHP Application Security

February 20th, 2005

I went through today and reorganized the PHP Application Security pages on the WACT Wiki. This mini wiki within a wiki is one of the most popular pages there. While the page has been popular, it hasn’t attracted much contribution.

I broke the existing entries up into four main categories. There is alot of structure here and thin content. Hopefully this will form an attractive nuisance for a collaborative effort to fill in some of the entries.

  • A Catalog of Security Vulnerabilities – Bad Security Smells.
  • A Catalog of Security Attacks – Attacks against PHP Applications and how to foil them.
  • A Catalog of Security Sensitive Functions – A List of PHP functions and their security implications.
  • A Catalog of Secure Practices – Best practices for secure applications.

I’ll probably start filling in the information the next time I go out of town and have internet access. I find it soothing when I am away from my standard development environment to google for security articles and summarize the information on the wiki. Thats how these pages were born.

Yes, I’m a geek.

Filed Under

  • PHP

Related Posts

  • PHP Security Ramblings
  • Improving Web Application Installation as a Security Imperative
  • PHP first impressions from a J2EE programmer
  • Documentation versus Productivity?
  • The value of MVC
You can leave a response, or trackback from your own site.

6 Responses to “PHP Application Security”

  1. scott reynen says:
    2/21/2005 at 4:54 am

    catalog links are empty.

  2. Chris Shiflett says:
    2/21/2005 at 12:14 pm

    I think it’s a good resource. We’ve linked to it in the PHPSC Library:

    http://phpsec.org/library/

    I’m not sure what to tell you about attracting more contributions. I’ve been considering something that utilizes http://del.icio.us/ for making our library more useful and current. Maybe you can consider something similar – people can contribute links and descriptions by tagging something with “wact-phpsec”, and your work can be reduced to moderating these submissions.

    Anyway, that’s a random idea I’ve been working with. Let me know if you think of something particularly creative.

  3. admin says:
    2/21/2005 at 12:15 pm

    Links fixed. Thanks for letting me know.

  4. admin says:
    2/21/2005 at 12:23 pm

    Thanks, Chris,
    http://del.icio.us/tag/php+security might work just as well.

  5. Sam says:
    2/22/2005 at 9:30 am

    Hi Jeff, Just wanted to let you know that your RSS feed is full of what appears to be BBCode rather than HTML. Thought you’d like to know.

  6. Shalom says:
    2/23/2005 at 8:06 am

    I had the same problem as Sam did.
    Keep up the good job..

Leave a Reply

Click here to cancel reply.

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

code: use [code=php][/code].

Comment Preview

    Subscribe Feed
    Share Subscribe to this blog…
    Share Bookmark or share this page…
  • About

    My name is Jeff Moore. I'm a PHP programmer living in San Francico and working for a startup.

    More about me…

  • Categories (Home)

    • Agile Methods (14)
    • Mac (14)
    • Misc (17)
    • Open Source (14)
    • PHP (98)
    • Software Design (29)
    • Usability (14)
    • Web Design (20)
  • Recent Comments

    • Benchmarking PHP's Magic Methods  12
      Article Marketing Strategy, Magento Development, Vance Lucas [...]
    • Improved Error Messages in PHP 5  32
      Terry Nessel, css, Amsterdam [...]
    • Keywords and Language Simplicity  11
      kim kardashian sex tape price, nokia, per Rechnung bestellen [...]
    • flickr case study  3
      bookmarking demon software, php-trivandrum.org, Harry Fuecks
    • rsync to remote server via ssh  7
      Burton Haynes, James, Mike [...]
    • Yahoo YUI wins JavaScript Library Wars  10
      Lera Bride, Scott, Jeff [...]
    • OOP is Mature, not Dead  15
      Avery Depew, Fernando, deltawing [...]
    • Ruby versus PHP or There and Back Again  10
      Solar Pumps, Amsterdam, Hari K T [...]
    • Looking Towards the Cloud  22
      Driver License, Jamel Sawyer, enculez. [...]
    • ZendCon: Writing Maintainable PHP Code  8
      IT Ninja, nicopico, Arif [...]
  • Recent Posts

    • ZendCon: Writing Maintainable PHP Code
    • Looking Towards the Cloud
    • Holiday Tech Support
    • Closures are coming to PHP
    • php | tek Wrapup
    • php | tek 2008
    • Sarah Snow Stever
    • Benchmarking PHP’s Magic Methods
    • The Endpoints of the Scale of Stupidity on Video
    • Working with PHP 5 in Mac OS X 10.5 (Leopard)
  • Site

    • Archives
    • Log in
  • Search