Published News » Security


Security »

This article will tell you about various vulnerabilities in PHP Website. We will discuss the common mistakes in php sites and also tell how to correct them. Read More
Posted by girish.r 260 days ago (http://mrbool.com)
Discuss  | Read MoreBury | Tweet This | Tagged: vulnerabilities php websites
Add To 

Security »

Brief recommendations to avoid SQL-Injection attacks with PHP. The importance of database users within our Web applications Read More
Posted by girish.r 470 days ago (http://gonzalo123.wordpress.com)
Discuss  | Read MoreBury | Tweet This | Tagged: how to protect sql injection php
Add To 

Security »

PHP 5.3.9 release was mostly meant to fix a security bug, but it introduced a new more serious bug. PHP 5.3.10 was just released to fix this issue. Meanwhile Debian Linux maintainers decided to stop enabling the Suhosin extension by default. This extension is used by several Linux distributions to provide protection against present and future security bugs of PHP. Read this article to learn mor Read More
Posted by girish.r 472 days ago (http://www.phpclasses.org)
Discuss  | Read MoreBury | Tweet This | Tagged: security bug php
Add To 

Security »

PHP is widely used for various of web development. However, misconfigured server-side scripting would create all sorts of problem. And here are php security best practices that you should aware when configuring PHP securely. Nowadays most of the web servers are operated under Linux environment (like: Ubuntu, Debian...etc). Hence, in the following article, I am going to use list top 10 ways to enh Read More
Posted by girish.r 481 days ago (http://www.ansoncheung.tk)
Discuss  | Read MoreBury | Tweet This | Tagged: php security practices sys admins
Add To 

Security »

Back from my extended leave of absence, I’ll re-open the dusty cobwebbed depths of this blog to echo the sentiments of Paul Reinheimer in his recent article “Cookies don’t replace Sessions“. The topic is actually an old one since Ruby On Rails has adopted the strategy of storing application session data in cookies by default (take note, performance hounds). Read More
Posted by girish.r 482 days ago (http://blog.astrumfutura.com)
Discuss  | Read MoreBury | Tweet This | Tagged: storing session data cookies problems security concerns
Add To 

Security »

You’ve heard of countless website and database breaches—and you’ve probably asked yourself how the attackers were able to get in. In many cases, minor vulnerabilities can be exploited to extend the attacker’s foothold and eventually compromise the entire server. In this six-part blog series, we will walk you through the process of completely compromising a target server on a recent web applicatio Read More
Posted by girish.r 693 days ago (http://blogs.captechventures.com)
Discuss  | Read MoreBury | Tweet This | Tagged: security software assurance vulnerabilities web applications
Add To 

Security »

Since the thing went public before new PHP version has been released, I present full details of the latest PHP vulnerability I reported - together with some sweet demo exploit. The issue was found with fuzzing being part of my recent file upload research. And I still have some more to show in the future :) Read More
Posted by girish.r 702 days ago (http://css.dzone.com)
Discuss  | Read MoreBury | Tweet This | Tagged: file path injection security
Add To 

Security »

Discover the habits PHP developers should get into to implement Web applications that have both characteristics. Read More
Posted by girish.r 728 days ago (http://www.ibm.com)
Discuss  | Read MoreBury | Tweet This | Tagged: habits writing secure php apps
Add To 

Security »

This rant is dedicated to my favourite gcc moronmaintainer, Andrew Pinski. Read More
Posted by girish.r 861 days ago (http://blog.andreas.org)
Discuss  | Read MoreBury | Tweet This | Tagged: php strtod denial of service bug
Add To 

Security »

Web developers are in a lather following the discovery of a bug in the PHP programming language that causes computers to freeze when they process certain numerical values with large numbers of decimal places. Read More
Posted by girish.r 867 days ago (http://www.theregister.co.uk)
Discuss  | Read MoreBury | Tweet This | Tagged: php apps bug
Add To 

Security »

Here are few concerns we should take into consideration when developing application using PHP. Read More
Posted by girish.r 933 days ago (http://www.satya-weblog.com)
Discuss  | Read MoreBury | Tweet This | Tagged: php security error reporting
Add To 

Security »

According to Wikipedia, SQL injection is a code injection technique that exploits a security vulnerability occurring in the database layer of an application. The vulnerability is present when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or Read More
Posted by girish.r 940 days ago (http://www.aafrin.com)
Discuss  | Read MoreBury | Tweet This | Tagged: vulnerable sql injection attacks
Add To 

Security »

Securing PHP code Read More
Posted by girish.r 967 days ago (http://www.php-code.net)
Discuss  | Read MoreBury | Tweet This | Tagged: securing sql injections session fixation session hijacking xss
Add To 

Security »

It looks like the attacker got access to the Gmail account that was used for managing the domain. He set up a filter on the inbox forwarding all incoming mails to another E-Mail address. This way he also got access to our registrar GoDaddy and transfered our domain to the registrar OnlineNic. We contacted the GoDaddy Undo department but haven't got an answer yet. Read More
Posted by girish.r 974 days ago (http://www.xajax-project.org)
Discuss  | Read MoreBury | Tweet This | Tagged: xajax stolen gmail hijack
Add To 

Security »

The first part of a short tutorial about securing PHP applications. Read More
Posted by girish.r 982 days ago (http://www.php-code.net)
Discuss  | Read MoreBury | Tweet This | Tagged: php php secure code security issues tutorial
Add To 

If you're having problems with server load due to high volume of traffic you can try getting fast cheap web hosting for your sites. Although web hosting is part of the solution you also need to consider other bandwidth heavy website applications.