Entries tagged as php-sicherheit
Monday, April 2. 2012
To complete the trinity of infamy: There is no Suhosin for PHP 5.4.0 either.
The patch is no longer bundled with distribution PHP. I have fired a mail to i0n1c about this but he seems to be in transit currently. The extension (0.9.33) does not compile with PHP 5.4.0 because of the copious API changes.
Update: There is now a new version of Suhosin that is compatible with PHP 5.4.0 and 5.4.1. You can download it from Stefan Esser’s Github account (.tar.gz .zip). It compiles and runs well with PHP 5.4.0-3 (Debian Wheezy).
PHP 5.4.0-3 (cli) (built: Mar 21 2012 20:33:26) Copyright (c) 1997-2012 The PHP Group Zend Engine v2.4.0, Copyright (c) 1998-2012 Zend Technologies with Suhosin v0.9.34-dev, Copyright (c) 2007-2012, by SektionEins GmbH
Thanks to andro for pointing this out. There is an installation howto over on php-security.net.
Thursday, September 11. 2008
It is not usually my custom to comment negatively or nitpick on other people's articles in magazines, especially not in magazines I have written for. This time however, I really must raise my voice to point out a couple of (well, actually a lot of) issues in an article about SQL injection in the current (October/November) issue of the german "PHP Magazin". I stumbled upon this when Pelle Boese of Mobile SEO fame told me about it.
As a couple of you should still remember, I wrote for that magazine until about one and a half years ago. I stopped writing for a couple of reasons. First and foremost, my shift towards Grid computing, my master's thesis and work took too much time. However, the, let's say, lean editorial process always kinda weirded me out. Mostly, manuscripts were printed as written, with no editorial changes at all. This is very trusting, but sometimes leads to fuck-ups like the one below.
Continue reading "Warning about the article "SQL Injection" in current "PHP Magazin""
Tuesday, July 1. 2008
Gerade kam eine Mail von Google:
wir bedanken uns für Ihre Teilnahme beim Empfehlungsprogramm von
AdSense. In der letzten Augustwoche werden wir das
AdSense-Empfehlungsprogramm einstellen. Danach werden keine
Anzeigen mit dem AdSense-Empfehlungscode mehr angezeigt.
Ich hatte mal kurzzeitig Empfehlungen auf ein paar Seiten (u.a. auch hier und dort), die Rate war aber unter aller Sau. Das scheint auch der Gugelhupf erkannt zu haben und das komplette Programm wird eingestellt.
Ohne großartige Ursachenforschung betreiben zu wollen (das können andere sicher besser, die sich mehr mit der Thematik beschäftigen): Mir fiel beim ersten Drüberschauen auf, daß die Anzahl der wirklich ordentlichen Werbepartner (die nicht z.B. mit einem Handlexikon ihre englischen Recommendations übersetzt haben) begrenzt war, Targetting auf originär deutsche Angebote schwer fiel (nur mit Kreditkarte bezahlbare englischsprachige Online-SPiele z.b. konvertieren mal so gar nicht) und das gesamte Recommendations-Programm einen eher unfertigen Eindruck machte. Aber das nur von mir als subjektive Meinung.
Monday, March 12. 2007
With the last entry in this blog being over 2 months old, I guess it’s time for a quick update. Actually, not much has changed. I am in the middle of my master’s thesis, lagging behind schedule as usual, and in parallel trying to get past my last exams for university. Doing both in parallel is not as much fun as you might think, especially with some other stuff looming behind. I have successfully deployed a couple of customers in the last weeks, most notably the folks at SwooDoo. Their PHP-MySQL-AJAX-driven flight search engine is definitely one of those useful sites that I’m proud to host. The second edition of our book, PHP-Sicherheit, is now under wraps, expanded by about 50 pages. I have written up a chapter on ext/filter (with a mixed recommendation) and expanded the web server filtering chapter by mod_parmguard. Other than that, Stefan has completely rewritten the chapter on “Hardening PHP” and we have changed a whole lot of stuff that was either outdated or included some tiny little errors. I wouldn’t go as far as to say you need to buy this book if you don’t have the first edition, but if you don’t have it at all, wait until late march to grab your copy. Next weekend, I’ll be presenting some funny XSS stuff at the Heise booth on CeBIT (Hall 5, Booth E38). If someone wants to meet me at the fair, please drop me a line ASAP. Apart from that, the next time I’ll be visible in the PHP community is the PHP Conference Spring Edition taking place in Stuttgart May 21 - 23. I’ll be presenting XSS stuff on the Webinale part of the conference. Due to time constraints, I won’t be present for more than 2 days, though - so probably I’ll leave straight after my session. Why is that? My thesis is due on the 31st, so go figure. 
Thursday, November 9. 2006
I already blogged this at our PHP Security Blog, but it is not (yet? hey Toby ) aggregated on planet-php, so here goes again.
You can now download my session slides for the full-day workshop on PHP security - unfortunately for my international readers, they are in German. If that doesn’t scare you (because you got taught lots of useful german phrases in the last days, right Caitlin? ), you can get them here:PHP Sicherheit Workshop.
If you need a little explanation on the PHP Security Quiz by Mayflower, just read the extended entry.
Continue reading "PHP Conference 2006 - Session Slides and Quiz answers"
I already blogged this at our PHP Security Blog, but it is not (yet? hey Toby ) aggregated on planet-php, so here goes again.
You can now download my session slides for the full-day workshop on PHP security - unfortunately for my international readers, they are in German. If that doesn’t scare you (because you got taught lots of useful german phrases in the last days, right Caitlin? ), you can get them here:PHP Sicherheit Workshop.
If you need a little explanation on the PHP Security Quiz by Mayflower, just read the extended entry.
Continue reading "PHP Conference 2006 - Session Slides and Quiz answers"
Monday, February 6. 2006
Für alle, die schon darauf gewartet haben: Peters und mein Buch, “PHP-Sicherheit”, ist endlich da! Ihr könnt das Werk, auf das wir im Übrigen ziemlich stolz sind, bei Amazon und direkt beim Verlag bestellen. Für die unvermeidlichen Errata gibts eine eigene Website: PHP-Sicherheit.de. 
For everyone who’s been waiting for it: Peter’s and my book, “PHP-Sicherheit” (in german only) is finally available. You can order the book - of which we’re very proud - via amazon.de or directly from the publisher. There’s going to be an errata/updates web site under PHP-Sicherheit.de.
Wednesday, November 9. 2005
That’s it - I’m home again, after almost four extremely rewarding and interesting days at the International PHP Conference in Frankfurt. The conference offered a chance to get together with all the cool guys from the international community, mix and mingle, drink lots of beer (my bar invoice was around 80 bucks) and of course hack at PHP. Since we had our own booth for the Hardened-PHP Project, we had the opportunity to pitch or little thingy to a wider base of interested developers and administrators, and the discussions at the booth sparked some new ideas for the Hardening Patch. We were also able to show off two advance copies of my (and my coauthor Peter Prochaska’s) first book, “PHP-Sicherheit”. It is the first german book dedicated to the security of our favorite scripting language, and after having it under public scrutiny for three days, I’m now confident it’s gonna be a success. Thanks to everyone for their feedback! For everyone who’s been in one of my talks, thanks for your interest to you guys and see you on the next conference. I will upload the slides to both presentations to my web server and notify everyone with a separate posting.
Thursday, November 3. 2005
As usual, I will be in attendance of the International PHP Conference in Frankfurt/Germany again, marking my 7th (or 8th, including the Amsterdam conferences) participation in this event. This year, however, promises to be a very special conference. Exciting things are going to happen - read more in the extended entry.
Continue reading "International PHP Conference 2005"
Sunday, July 10. 2005
Seit dem Wochenende ist die neue Website des Hardened-PHP Project online, an dem ich mitwirke. Zusätzlich zum mittlerweile in der Version 0.3.2 erschienenen Hardening-Patch für PHP werden wir eine Sammlung aller von uns herausgegebenen Advisories sowie weiteren PHP-Security bezogenen Content anbieten. Und: Man kann uns mieten, um als Bugjäger eigene PHP-Applikationen auf Securityprobleme zu untersuchen.
Wednesday, June 29. 2005
Kein großes blabla, direkt updaten! Eine kritische xmlrpc-Lücke ist in allen S9Y-Versionen vorhanden, wie Sebastian Nohn schreibt.
Direkter Download: http://www.nohn.net/downloads/serendipity-0.8.2.tar.bz2
|