<?xml version="1.0" encoding="iso-8859-1"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>Web Security Magazine</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/" />
    <link rel="self" type="application/atom+xml" href="http://security.phpmagazine.net/atom.xml" />
   <id>tag:security.phpmagazine.net,2008://40</id>
    <link rel="service.post" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40" title="Web Security Magazine" />
    <updated>2008-06-25T18:44:08Z</updated>
    
 
<entry>
    <title>HTML Purifier, Standards-Compliant HTML Filtering</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/2008/06/html_purifier_standardscomplia.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40/entry_id=6317" title="HTML Purifier, Standards-Compliant HTML Filtering" />
    <id>tag:security.phpmagazine.net,2008://40.6317</id>
    
    <published>2008-06-20T21:48:18Z</published>
    <updated>2008-06-25T18:44:08Z</updated>
    
    <summary>HTML Purifier is a standards-compliant HTML filter library written in PHP. HTML Purifier will not only remove all malicious code (better known as XSS) with a thoroughly audited, secure yet permissive whitelist, it will also make sure your documents are...</summary>
    <author>
        <name>Hatem</name>
        <uri>http://www.phpmagazine.net</uri>
    </author>
            <category term="Tools" />
    
    <content type="html" xml:lang="en" xml:base="http://security.phpmagazine.net/">
        HTML Purifier is a standards-compliant HTML filter library written in PHP. HTML Purifier will not only remove all malicious code (better known as XSS) with a thoroughly audited, secure yet permissive whitelist, it will also make sure your documents are...
    </content>
</entry>
<entry>
    <title>GreenSQL, Open Source Database Firewall Solution</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/2008/05/greensql_open_source_database.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40/entry_id=6276" title="GreenSQL, Open Source Database Firewall Solution" />
    <id>tag:security.phpmagazine.net,2008://40.6276</id>
    
    <published>2008-05-31T06:31:39Z</published>
    <updated>2008-05-31T06:40:14Z</updated>
    
    <summary>To keep your database safe from SQL injection attacks, GreenSQL is a new Open Source database firewall that you might give a try. GreenSQL works as a reverse proxy and has built in support for MySQL. The logic is based...</summary>
    <author>
        <name>Hatem</name>
        <uri>http://www.phpmagazine.net</uri>
    </author>
            <category term="Experience" />
            <category term="Tools" />
    
    <content type="html" xml:lang="en" xml:base="http://security.phpmagazine.net/">
        To keep your database safe from SQL injection attacks, GreenSQL is a new Open Source database firewall that you might give a try. GreenSQL works as a reverse proxy and has built in support for MySQL. The logic is based...
    </content>
</entry>
<entry>
    <title>Mass Iframe Attack Continue Infecting Sites</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/2008/04/mass_iframe_attack_continue_in.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40/entry_id=6241" title="Mass Iframe Attack Continue Infecting Sites" />
    <id>tag:security.phpmagazine.net,2008://40.6241</id>
    
    <published>2008-04-19T07:19:36Z</published>
    <updated>2008-04-19T07:53:22Z</updated>
    
    <summary>Last month we started hearing reports about an Iframe injection that infected thousands of websites and servers. The malware in question is a variant of Zlob and attempt to install itself in the client-side throught an ActiveX, as an unsigned...</summary>
    <author>
        <name>Hatem</name>
        <uri>http://www.phpmagazine.net</uri>
    </author>
            <category term="Alert" />
    
    <content type="html" xml:lang="en" xml:base="http://security.phpmagazine.net/">
        Last month we started hearing reports about an Iframe injection that infected thousands of websites and servers. The malware in question is a variant of Zlob and attempt to install itself in the client-side throught an ActiveX, as an unsigned...
    </content>
</entry>
<entry>
    <title>Facebook code revealed : Mod_PHP Leakage is not PHP fault</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/2007/08/facebook_code_revealed_mod_php.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40/entry_id=6102" title="Facebook code revealed : Mod_PHP Leakage is not PHP fault" />
    <id>tag:security.phpmagazine.net,2007://40.6102</id>
    
    <published>2007-08-13T18:29:04Z</published>
    <updated>2007-08-13T18:52:31Z</updated>
    
    <summary>When a server is not well configured and the system administrator didn&apos;t make his job correctly, there is no reason to blame PHP. It&apos;s not in defense of the PHP scripting language, but to be realistic and to give to...</summary>
    <author>
        <name>Hatem</name>
        <uri>http://www.phpmagazine.net</uri>
    </author>
            <category term="Experience" />
    
    <content type="html" xml:lang="en" xml:base="http://security.phpmagazine.net/">
        When a server is not well configured and the system administrator didn&apos;t make his job correctly, there is no reason to blame PHP. It&apos;s not in defense of the PHP scripting language, but to be realistic and to give to...
    </content>
</entry>
<entry>
    <title>PHPIDS, PHP-Intrusion Detection System</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/2007/06/phpids_phpintrusion_detection.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40/entry_id=6007" title="PHPIDS, PHP-Intrusion Detection System" />
    <id>tag:security.phpmagazine.net,2007://40.6007</id>
    
    <published>2007-06-20T09:15:18Z</published>
    <updated>2007-06-20T09:29:54Z</updated>
    
    <summary>PHPIDS is a security PHP project which aims to provide a security application layer to protect any PHP web application. Using PHPIDS you will be able to see who is attacking your site and how, while keeping your project safe....</summary>
    <author>
        <name>Hatem</name>
        <uri>http://www.phpmagazine.net</uri>
    </author>
            <category term="Experience" />
            <category term="Tools" />
    
    <content type="html" xml:lang="en" xml:base="http://security.phpmagazine.net/">
        PHPIDS is a security PHP project which aims to provide a security application layer to protect any PHP web application. Using PHPIDS you will be able to see who is attacking your site and how, while keeping your project safe....
    </content>
</entry>
<entry>
    <title>Securing PHP Applications</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/2007/05/securing_php_applications.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40/entry_id=5939" title="Securing PHP Applications" />
    <id>tag:security.phpmagazine.net,2007://40.5939</id>
    
    <published>2007-05-16T14:57:00Z</published>
    <updated>2007-05-16T20:07:38Z</updated>
    
    <summary>Ilia Alshanetsky posted his talks over the PHP|Tek 2007. The two tutorials took 6 hours of talking, waw ! And it&apos;s quite interesting. One of the tutorials is about Securing PHP Applications (PDF) and include a security roundup for PHP...</summary>
    <author>
        <name>Hatem</name>
        <uri>http://www.phpmagazine.net</uri>
    </author>
            <category term="General" />
    
    <content type="html" xml:lang="en" xml:base="http://security.phpmagazine.net/">
        Ilia Alshanetsky posted his talks over the PHP|Tek 2007. The two tutorials took 6 hours of talking, waw ! And it&apos;s quite interesting. One of the tutorials is about Securing PHP Applications (PDF) and include a security roundup for PHP...
    </content>
</entry>
<entry>
    <title>PhpSecInfo 0.2.1 Released</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/2007/04/phpsecinfo_021_released.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40/entry_id=5802" title="PhpSecInfo 0.2.1 Released" />
    <id>tag:security.phpmagazine.net,2007://40.5802</id>
    
    <published>2007-04-08T19:49:10Z</published>
    <updated>2007-04-08T19:53:59Z</updated>
    
    <summary>PHP Security Consortium released PhpSecInfo 0.2.1 an equivalent to the phpinfo() function that reports security information about the PHP environment, and offers suggestions for improvement. The new release fixed some significant bugs, from the changelog : uid and gid tests...</summary>
    <author>
        <name>Hatem</name>
        <uri>http://www.phpmagazine.net</uri>
    </author>
            <category term="Tools" />
    
    <content type="html" xml:lang="en" xml:base="http://security.phpmagazine.net/">
        PHP Security Consortium released PhpSecInfo 0.2.1 an equivalent to the phpinfo() function that reports security information about the PHP environment, and offers suggestions for improvement. The new release fixed some significant bugs, from the changelog : uid and gid tests...
    </content>
</entry>
<entry>
    <title>Armorize CodeSecure, On-Demand PHP Source Code Analysis</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/2007/04/armorize_codesecure_ondemand_p.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40/entry_id=5781" title="Armorize CodeSecure, On-Demand PHP Source Code Analysis" />
    <id>tag:security.phpmagazine.net,2007://40.5781</id>
    
    <published>2007-04-03T10:39:51Z</published>
    <updated>2007-04-03T10:45:23Z</updated>
    
    <summary>Armorize Technologies have an interesting on-demand PHP source code analysis service CodeSecure. The product developed specifically for PHP, represents a powerful tool for identifying and fixing vulnerabilities in custom developed PHP applications. CodeSecure utilizes the latest verification technology to analyze...</summary>
    <author>
        <name>Hatem</name>
        <uri>http://www.phpmagazine.net</uri>
    </author>
            <category term="Tools" />
    
    <content type="html" xml:lang="en" xml:base="http://security.phpmagazine.net/">
        Armorize Technologies have an interesting on-demand PHP source code analysis service CodeSecure. The product developed specifically for PHP, represents a powerful tool for identifying and fixing vulnerabilities in custom developed PHP applications. CodeSecure utilizes the latest verification technology to analyze...
    </content>
</entry>
<entry>
    <title>Will PHP Be More Secure On March 2007 ?</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/2007/03/will_php_be_more_secure_on_mar.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40/entry_id=5681" title="Will PHP Be More Secure On March 2007 ?" />
    <id>tag:security.phpmagazine.net,2007://40.5681</id>
    
    <published>2007-03-05T15:10:00Z</published>
    <updated>2007-03-05T16:27:16Z</updated>
    
    <summary>Month of PHP Bugs already started, and there is until today 11 Bugs posted. The goal is to make PHP more secure and make people and developers aware of insecurities in the language. Day by day vulnerabilities vulnerabilities in the...</summary>
    <author>
        <name>Hatem</name>
        <uri>http://www.phpmagazine.net</uri>
    </author>
            <category term="Alert" />
            <category term="Experience" />
    
    <content type="html" xml:lang="en" xml:base="http://security.phpmagazine.net/">
        Month of PHP Bugs already started, and there is until today 11 Bugs posted. The goal is to make PHP more secure and make people and developers aware of insecurities in the language. Day by day vulnerabilities vulnerabilities in the...
    </content>
</entry>
<entry>
    <title>March 2007, The Month of PHP Bugs</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/2007/02/march_2007_the_month_of_php_bu.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40/entry_id=5635" title="March 2007, The Month of PHP Bugs" />
    <id>tag:security.phpmagazine.net,2007://40.5635</id>
    
    <published>2007-02-22T16:00:24Z</published>
    <updated>2007-02-22T16:08:32Z</updated>
    
    <summary>Slashdotted, As previously announced in an interview with Stefan Esser, March 2007 will be the month of PHP Bugs. A new initiative which goal is to make PHP more secure and discuss with more transparency the security issues related to...</summary>
    <author>
        <name>Hatem</name>
        <uri>http://www.phpmagazine.net</uri>
    </author>
            <category term="Experience" />
    
    <content type="html" xml:lang="en" xml:base="http://security.phpmagazine.net/">
        Slashdotted, As previously announced in an interview with Stefan Esser, March 2007 will be the month of PHP Bugs. A new initiative which goal is to make PHP more secure and discuss with more transparency the security issues related to...
    </content>
</entry>
<entry>
    <title>Is your website hackable? Why you need to worry</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/2007/02/is_your_website_hackable_why_y.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40/entry_id=5574" title="Is your website hackable? Why you need to worry" />
    <id>tag:security.phpmagazine.net,2007://40.5574</id>
    
    <published>2007-02-10T06:31:39Z</published>
    <updated>2007-02-10T06:47:33Z</updated>
    
    <summary>Apocalypse Now Just because you think your data is safe does not mean your database of sensitive organization information has not already been cloned and is resident elsewhere ready to be sold to the highest bidder. To make matters worse,...</summary>
    <author>
        <name>Hatem</name>
        <uri>http://www.phpmagazine.net</uri>
    </author>
            <category term="Experience" />
    
    <content type="html" xml:lang="en" xml:base="http://security.phpmagazine.net/">
        Apocalypse Now Just because you think your data is safe does not mean your database of sensitive organization information has not already been cloned and is resident elsewhere ready to be sold to the highest bidder. To make matters worse,...
    </content>
</entry>
<entry>
    <title>SecurityFocus Interview PHP Security Expert Stefan Esser</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/2007/02/securityfocus_interview_php_se.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40/entry_id=5567" title="SecurityFocus Interview PHP Security Expert Stefan Esser" />
    <id>tag:security.phpmagazine.net,2007://40.5567</id>
    
    <published>2007-02-08T14:35:45Z</published>
    <updated>2007-02-08T14:38:34Z</updated>
    
    <summary>SecurityFocus posted an interview with Stefan Esser, the founder of both the Hardened-PHP Project and the PHP Security Response Team (which he recently left). In the interview Federico Biancuzzi discussed with him how the PHP Security Response Team works, why...</summary>
    <author>
        <name>Hatem</name>
        <uri>http://www.phpmagazine.net</uri>
    </author>
            <category term="Interview" />
    
    <content type="html" xml:lang="en" xml:base="http://security.phpmagazine.net/">
        SecurityFocus posted an interview with Stefan Esser, the founder of both the Hardened-PHP Project and the PHP Security Response Team (which he recently left). In the interview Federico Biancuzzi discussed with him how the PHP Security Response Team works, why...
    </content>
</entry>
<entry>
    <title>Serious Gmail Vulnerability discovered</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/2007/01/serious_gmail_vulnerability_di.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40/entry_id=5442" title="Serious Gmail Vulnerability discovered" />
    <id>tag:security.phpmagazine.net,2007://40.5442</id>
    
    <published>2007-01-01T14:17:30Z</published>
    <updated>2007-01-01T11:22:16Z</updated>
    
    <summary>A serious Gmail security bug have been reported where anyone can access your contact list just visiting a malicious page. The Javascript have been made public probably for usage with Google Docs since the url is linked from there, but...</summary>
    <author>
        <name>Hatem</name>
        <uri>http://www.phpmagazine.net</uri>
    </author>
            <category term="Alert" />
    
    <content type="html" xml:lang="en" xml:base="http://security.phpmagazine.net/">
        A serious Gmail security bug have been reported where anyone can access your contact list just visiting a malicious page. The Javascript have been made public probably for usage with Google Docs since the url is linked from there, but...
    </content>
</entry>
<entry>
    <title>Stefan Esser retired from PHP security team</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/2006/12/stefan_esser_retired_from_php.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40/entry_id=5350" title="Stefan Esser retired from PHP security team" />
    <id>tag:security.phpmagazine.net,2006://40.5350</id>
    
    <published>2006-12-14T12:17:49Z</published>
    <updated>2006-12-14T09:21:25Z</updated>
    
    <summary>Stefan have announced officially on his blog that he&apos;s finally retired from the PHP Security Response Team. The reasons are many, but according to Stefan the most important reason was that he realised that any attempt to improve the security...</summary>
    <author>
        <name>Hatem</name>
        <uri>http://www.phpmagazine.net</uri>
    </author>
            <category term="General" />
    
    <content type="html" xml:lang="en" xml:base="http://security.phpmagazine.net/">
        Stefan have announced officially on his blog that he&apos;s finally retired from the PHP Security Response Team. The reasons are many, but according to Stefan the most important reason was that he realised that any attempt to improve the security...
    </content>
</entry>
<entry>
    <title>Anonymizing RFI attacks through Google</title>
    <link rel="alternate" type="text/html" href="http://security.phpmagazine.net/2006/11/anonymizing_rfi_attacks_throug.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://phpmagazine.net/cgi-bin/pub/mt-atom.cgi/weblog/blog_id=40/entry_id=5256" title="Anonymizing RFI attacks through Google" />
    <id>tag:security.phpmagazine.net,2006://40.5256</id>
    
    <published>2006-11-23T20:30:00Z</published>
    <updated>2006-11-23T17:35:10Z</updated>
    
    <summary>Slashdotted today an experience to anonymizing RFI Attacks Through Google. An interesting approach that search engines should be aware, and if it could be done using Google crawler, it could be done also using any other spider : Noam Rathaus...</summary>
    <author>
        <name>Hatem</name>
        <uri>http://www.phpmagazine.net</uri>
    </author>
            <category term="Experience" />
    
    <content type="html" xml:lang="en" xml:base="http://security.phpmagazine.net/">
        Slashdotted today an experience to anonymizing RFI Attacks Through Google. An interesting approach that search engines should be aware, and if it could be done using Google crawler, it could be done also using any other spider : Noam Rathaus...
    </content>
</entry>

</feed> 