Professional PHP

PHP Programming, Web Development, PHP Advocacy and PHP Best Practices.
« Zend Framework Webcast
PHP Book sales trends versus Java and Ruby »

Improving Web Application Installation as a Security Imperative

December 7th, 2005

It looks there is a Mambo worm out now. I read Hackers Hitting Popular Apps a couple of weeks ago and it mentioned that hackers are targeting PHP apps among other things. Dog bites man for some. More interesting was this quote:

“The bottom line is that security has been set back nearly six years in the past 18 months,” Alan Paller, director of research for the SANS Institute, wrote in an E-mail. “Six years ago, attackers targeted operating systems and the operating system vendors didn’t do automated patching. In the intervening years, automated patching protected everyone from government to grandma. Now the attackers are targeting popular applications, and the vendors of those applications do not do automated patching.”

I’ve advocated better web application installation for a while, but as a usability issue. Increasingly, it is also a security issue. Just another example of why I think the PEAR installer is important. (and why I hope Zend PHP Framework is released on a PEAR channel.)

categories PHP
tags pear, pear-installer, php-deployment, php-security

Related Posts

  • PHP Application Security
  • PHP Security Ramblings
  • Shipping Software is fun
  • php | tek Wrapup
  • Installing PEAR Based Applications
You can leave a response, or trackback from your own site.

One Response to “Improving Web Application Installation as a Security Imperative”

  1. #1 Sandro Groganz responds...
    December 8th, 2005 at 12:12 am

    The eZ publish Network Edition ships with an automated update manager which allows for automated patching in case there’s a security flaw: http://ez.no/services/ez_publish_network

Leave a Reply

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

code: use [code=php][/code].

Comment Preview

  • Search

  • Subscribe

    Subscribe All Posts
    Subscribe All Comments
    Subscribe All Bookmarks
    Subscribe with Bloglines Subscribe with My Yahoo Add to netvibes Subscribe in NewsGator Online Add to Google
  • Share This

  • Categories (Home)

    • Agile Methods (14)
    • Mac (14)
    • Misc (16)
    • Open Source (14)
    • PHP (95)
    • Software Design (28)
    • Usability (14)
    • WACT (7)
    • Web Design (20)
  • Recent Comments

    • goto in PHP  51
      car49b, mp7df, mp2be [...]
    • Mac Mini and PHP  17
      car551, , mp111 [...]
    • The PHP scalability saga continues  21
      carcaa, mp1e5, mpae1 [...]
    • WordPress BBCode Plugin  24
      loul, ????????, smolenskiy [...]
    • PHP 5.1 is out  5
      Gorrdon, Joey, alex [...]
    • The value of MVC  10
      Ron, Caren Goodman, Joe [...]
    • PHP Development From Java Architects Eye  10
      big, Bobrila, FelhoBacsi [...]
    • Friendster wrapup: does MySQL scale  11
      autodd4, autoc37, carc20 [...]
    • Keywords and Language Simplicity  8
      sergio, Programmer, Handy [...]
    • Working with PHP 5 in Mac OS X 10.5 (Leopard)  109
      Casper, Andy V, Dedra Church [...]
    • Why is PHP Popular?  27
      booksbrands.ru, megaartic.ru, nedvvid.ru [...]
  • Pages

    • Tags
  • Recent Posts

    • php | tek Wrapup
    • php | tek 2008
    • Sarah Snow Stever
    • Benchmarking PHP’s Magic Methods
    • The Endpoints of the Scale of Stupidity on Video
    • Working with PHP 5 in Mac OS X 10.5 (Leopard)
    • Keywords and Language Simplicity
    • Improved Error Messages in PHP 5
    • Michigan Taxes Graphic Design Services
    • Ruby versus PHP or There and Back Again
  • Archives

    • 2008: May
    • 2007: Jan Feb Mar Apr May Sep Oct Nov
    • 2006: Jan Feb Mar Apr May Jun Jul Oct Nov Dec
    • 2005: Jan Feb Mar Apr May Sep Oct Nov Dec
    • 2004: Apr May Jun Jul Aug Sep Oct Nov
  • Menu

    • Register
    • Log in