Professional PHP

PHP Programming, Web Development, PHP Advocacy and PHP Best Practices.
« PHP first impressions from a J2EE programmer
Flawed Microbenchmarks »

PHP Application Security

February 20th, 2005

I went through today and reorganized the PHP Application Security pages on the WACT Wiki. This mini wiki within a wiki is one of the most popular pages there. While the page has been popular, it hasn’t attracted much contribution.

I broke the existing entries up into four main categories. There is alot of structure here and thin content. Hopefully this will form an attractive nuisance for a collaborative effort to fill in some of the entries.

  • A Catalog of Security Vulnerabilities - Bad Security Smells.
  • A Catalog of Security Attacks - Attacks against PHP Applications and how to foil them.
  • A Catalog of Security Sensitive Functions - A List of PHP functions and their security implications.
  • A Catalog of Secure Practices - Best practices for secure applications.

I’ll probably start filling in the information the next time I go out of town and have internet access. I find it soothing when I am away from my standard development environment to google for security articles and summarize the information on the wiki. Thats how these pages were born.

Yes, I’m a geek.

categories PHP
tags php-security

Related Posts

  • PHP Security Ramblings
  • Improving Web Application Installation as a Security Imperative
  • PHP first impressions from a J2EE programmer
  • Documentation versus Productivity?
  • Enterprise PHP
You can leave a response, or trackback from your own site.

6 Responses to “PHP Application Security”

  1. #1 scott reynen responds...
    February 21st, 2005 at 4:54 am

    catalog links are empty.

  2. #2 Chris Shiflett responds...
    February 21st, 2005 at 12:14 pm

    I think it’s a good resource. We’ve linked to it in the PHPSC Library:

    http://phpsec.org/library/

    I’m not sure what to tell you about attracting more contributions. I’ve been considering something that utilizes http://del.icio.us/ for making our library more useful and current. Maybe you can consider something similar - people can contribute links and descriptions by tagging something with “wact-phpsec”, and your work can be reduced to moderating these submissions.

    Anyway, that’s a random idea I’ve been working with. Let me know if you think of something particularly creative.

  3. #3 admin responds...
    February 21st, 2005 at 12:15 pm

    Links fixed. Thanks for letting me know.

  4. #4 admin responds...
    February 21st, 2005 at 12:23 pm

    Thanks, Chris,
    http://del.icio.us/tag/php+security might work just as well.

  5. #5 Sam responds...
    February 22nd, 2005 at 9:30 am

    Hi Jeff, Just wanted to let you know that your RSS feed is full of what appears to be BBCode rather than HTML. Thought you’d like to know.

  6. #6 Shalom responds...
    February 23rd, 2005 at 8:06 am

    I had the same problem as Sam did.
    Keep up the good job..

Leave a Reply

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

code: use [code=php][/code].

Comment Preview

  • Search

  • Subscribe

    Subscribe All Posts
    Subscribe All Comments
    Subscribe All Bookmarks
    Subscribe with Bloglines Subscribe with My Yahoo Add to netvibes Subscribe in NewsGator Online Add to Google
  • Share This

  • Categories (Home)

    • Agile Methods (14)
    • Mac (14)
    • Misc (16)
    • Open Source (14)
    • PHP (95)
    • Software Design (28)
    • Usability (14)
    • WACT (7)
    • Web Design (20)
  • Recent Comments

    • The PHP scalability saga continues  23
      mpc32, mp7c2, carcaa [...]
    • Friendster wrapup: does MySQL scale  15
      mp5e9, carfbe, carc1f [...]
    • goto in PHP  53
      mp83e, mp7c2, car49b [...]
    • Mac Mini and PHP  18
      mpcb6, car551, [...]
    • WordPress BBCode Plugin  24
      loul, ????????, smolenskiy [...]
    • PHP 5.1 is out  5
      Gorrdon, Joey, alex [...]
    • The value of MVC  10
      Ron, Caren Goodman, Joe [...]
    • PHP Development From Java Architects Eye  10
      big, Bobrila, FelhoBacsi [...]
    • Keywords and Language Simplicity  8
      sergio, Programmer, Handy [...]
    • Working with PHP 5 in Mac OS X 10.5 (Leopard)  109
      Casper, Andy V, Dedra Church [...]
    • Why is PHP Popular?  27
      booksbrands.ru, megaartic.ru, nedvvid.ru [...]
  • Pages

    • Tags
  • Recent Posts

    • php | tek Wrapup
    • php | tek 2008
    • Sarah Snow Stever
    • Benchmarking PHP’s Magic Methods
    • The Endpoints of the Scale of Stupidity on Video
    • Working with PHP 5 in Mac OS X 10.5 (Leopard)
    • Keywords and Language Simplicity
    • Improved Error Messages in PHP 5
    • Michigan Taxes Graphic Design Services
    • Ruby versus PHP or There and Back Again
  • Archives

    • 2008: May
    • 2007: Jan Feb Mar Apr May Sep Oct Nov
    • 2006: Jan Feb Mar Apr May Jun Jul Oct Nov Dec
    • 2005: Jan Feb Mar Apr May Sep Oct Nov Dec
    • 2004: Apr May Jun Jul Aug Sep Oct Nov
  • Menu

    • Register
    • Log in