<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0">
   <channel>
      <image>
      <link>http://security.phpmagazine.net/</link>
	<url>http://security.phpmagazine.net/images/logo.png</url>
       <title>Web Security Magazine</title>
      </image>
      <title>Web Security Magazine</title>
      <link>http://security.phpmagazine.net/</link>
      <description></description>
      <language>en</language>
      <copyright>Copyright 2008</copyright>
      <lastBuildDate>Fri, 20 Jun 2008 21:48:18 +0000</lastBuildDate>
      <docs>http://blogs.law.harvard.edu/tech/rss</docs> 

            <item>
         <title>HTML Purifier, Standards-Compliant HTML Filtering</title>
         <description>HTML Purifier is a standards-compliant HTML filter library written in PHP. HTML Purifier will not only remove all malicious code (better known as XSS) with a thoroughly audited, secure yet permissive whitelist, it will also make sure your documents are...</description>
         <link>http://security.phpmagazine.net/2008/06/html_purifier_standardscomplia.html</link>
         <guid>http://security.phpmagazine.net/2008/06/html_purifier_standardscomplia.html</guid>
         <category>Tools</category>
         <pubDate>Fri, 20 Jun 2008 21:48:18 +0000</pubDate>
      </item>
            <item>
         <title>GreenSQL, Open Source Database Firewall Solution</title>
         <description>To keep your database safe from SQL injection attacks, GreenSQL is a new Open Source database firewall that you might give a try. GreenSQL works as a reverse proxy and has built in support for MySQL. The logic is based...</description>
         <link>http://security.phpmagazine.net/2008/05/greensql_open_source_database.html</link>
         <guid>http://security.phpmagazine.net/2008/05/greensql_open_source_database.html</guid>
         <category>Tools</category>
         <pubDate>Sat, 31 May 2008 06:31:39 +0000</pubDate>
      </item>
            <item>
         <title>Mass Iframe Attack Continue Infecting Sites</title>
         <description>Last month we started hearing reports about an Iframe injection that infected thousands of websites and servers. The malware in question is a variant of Zlob and attempt to install itself in the client-side throught an ActiveX, as an unsigned...</description>
         <link>http://security.phpmagazine.net/2008/04/mass_iframe_attack_continue_in.html</link>
         <guid>http://security.phpmagazine.net/2008/04/mass_iframe_attack_continue_in.html</guid>
         <category>Alert</category>
         <pubDate>Sat, 19 Apr 2008 07:19:36 +0000</pubDate>
      </item>
            <item>
         <title>Facebook code revealed : Mod_PHP Leakage is not PHP fault</title>
         <description>When a server is not well configured and the system administrator didn&apos;t make his job correctly, there is no reason to blame PHP. It&apos;s not in defense of the PHP scripting language, but to be realistic and to give to...</description>
         <link>http://security.phpmagazine.net/2007/08/facebook_code_revealed_mod_php.html</link>
         <guid>http://security.phpmagazine.net/2007/08/facebook_code_revealed_mod_php.html</guid>
         <category>Experience</category>
         <pubDate>Mon, 13 Aug 2007 18:29:04 +0000</pubDate>
      </item>
            <item>
         <title>PHPIDS, PHP-Intrusion Detection System</title>
         <description>PHPIDS is a security PHP project which aims to provide a security application layer to protect any PHP web application. Using PHPIDS you will be able to see who is attacking your site and how, while keeping your project safe....</description>
         <link>http://security.phpmagazine.net/2007/06/phpids_phpintrusion_detection.html</link>
         <guid>http://security.phpmagazine.net/2007/06/phpids_phpintrusion_detection.html</guid>
         <category>Tools</category>
         <pubDate>Wed, 20 Jun 2007 09:15:18 +0000</pubDate>
      </item>
            <item>
         <title>Securing PHP Applications</title>
         <description>Ilia Alshanetsky posted his talks over the PHP|Tek 2007. The two tutorials took 6 hours of talking, waw ! And it&apos;s quite interesting. One of the tutorials is about Securing PHP Applications (PDF) and include a security roundup for PHP...</description>
         <link>http://security.phpmagazine.net/2007/05/securing_php_applications.html</link>
         <guid>http://security.phpmagazine.net/2007/05/securing_php_applications.html</guid>
         <category>General</category>
         <pubDate>Wed, 16 May 2007 14:57:00 +0000</pubDate>
      </item>
            <item>
         <title>PhpSecInfo 0.2.1 Released</title>
         <description>PHP Security Consortium released PhpSecInfo 0.2.1 an equivalent to the phpinfo() function that reports security information about the PHP environment, and offers suggestions for improvement. The new release fixed some significant bugs, from the changelog : uid and gid tests...</description>
         <link>http://security.phpmagazine.net/2007/04/phpsecinfo_021_released.html</link>
         <guid>http://security.phpmagazine.net/2007/04/phpsecinfo_021_released.html</guid>
         <category>Tools</category>
         <pubDate>Sun, 08 Apr 2007 19:49:10 +0000</pubDate>
      </item>
            <item>
         <title>Armorize CodeSecure, On-Demand PHP Source Code Analysis</title>
         <description>Armorize Technologies have an interesting on-demand PHP source code analysis service CodeSecure. The product developed specifically for PHP, represents a powerful tool for identifying and fixing vulnerabilities in custom developed PHP applications. CodeSecure utilizes the latest verification technology to analyze...</description>
         <link>http://security.phpmagazine.net/2007/04/armorize_codesecure_ondemand_p.html</link>
         <guid>http://security.phpmagazine.net/2007/04/armorize_codesecure_ondemand_p.html</guid>
         <category>Tools</category>
         <pubDate>Tue, 03 Apr 2007 10:39:51 +0000</pubDate>
      </item>
            <item>
         <title>Will PHP Be More Secure On March 2007 ?</title>
         <description>Month of PHP Bugs already started, and there is until today 11 Bugs posted. The goal is to make PHP more secure and make people and developers aware of insecurities in the language. Day by day vulnerabilities vulnerabilities in the...</description>
         <link>http://security.phpmagazine.net/2007/03/will_php_be_more_secure_on_mar.html</link>
         <guid>http://security.phpmagazine.net/2007/03/will_php_be_more_secure_on_mar.html</guid>
         <category>Alert</category>
         <pubDate>Mon, 05 Mar 2007 15:10:00 +0000</pubDate>
      </item>
            <item>
         <title>March 2007, The Month of PHP Bugs</title>
         <description>Slashdotted, As previously announced in an interview with Stefan Esser, March 2007 will be the month of PHP Bugs. A new initiative which goal is to make PHP more secure and discuss with more transparency the security issues related to...</description>
         <link>http://security.phpmagazine.net/2007/02/march_2007_the_month_of_php_bu.html</link>
         <guid>http://security.phpmagazine.net/2007/02/march_2007_the_month_of_php_bu.html</guid>
         <category>Experience</category>
         <pubDate>Thu, 22 Feb 2007 16:00:24 +0000</pubDate>
      </item>
            <item>
         <title>Is your website hackable? Why you need to worry</title>
         <description>Apocalypse Now Just because you think your data is safe does not mean your database of sensitive organization information has not already been cloned and is resident elsewhere ready to be sold to the highest bidder. To make matters worse,...</description>
         <link>http://security.phpmagazine.net/2007/02/is_your_website_hackable_why_y.html</link>
         <guid>http://security.phpmagazine.net/2007/02/is_your_website_hackable_why_y.html</guid>
         <category>Experience</category>
         <pubDate>Sat, 10 Feb 2007 06:31:39 +0000</pubDate>
      </item>
            <item>
         <title>SecurityFocus Interview PHP Security Expert Stefan Esser</title>
         <description>SecurityFocus posted an interview with Stefan Esser, the founder of both the Hardened-PHP Project and the PHP Security Response Team (which he recently left). In the interview Federico Biancuzzi discussed with him how the PHP Security Response Team works, why...</description>
         <link>http://security.phpmagazine.net/2007/02/securityfocus_interview_php_se.html</link>
         <guid>http://security.phpmagazine.net/2007/02/securityfocus_interview_php_se.html</guid>
         <category>Interview</category>
         <pubDate>Thu, 08 Feb 2007 14:35:45 +0000</pubDate>
      </item>
            <item>
         <title>Serious Gmail Vulnerability discovered</title>
         <description>A serious Gmail security bug have been reported where anyone can access your contact list just visiting a malicious page. The Javascript have been made public probably for usage with Google Docs since the url is linked from there, but...</description>
         <link>http://security.phpmagazine.net/2007/01/serious_gmail_vulnerability_di.html</link>
         <guid>http://security.phpmagazine.net/2007/01/serious_gmail_vulnerability_di.html</guid>
         <category>Alert</category>
         <pubDate>Mon, 01 Jan 2007 14:17:30 +0000</pubDate>
      </item>
            <item>
         <title>Stefan Esser retired from PHP security team</title>
         <description>Stefan have announced officially on his blog that he&apos;s finally retired from the PHP Security Response Team. The reasons are many, but according to Stefan the most important reason was that he realised that any attempt to improve the security...</description>
         <link>http://security.phpmagazine.net/2006/12/stefan_esser_retired_from_php.html</link>
         <guid>http://security.phpmagazine.net/2006/12/stefan_esser_retired_from_php.html</guid>
         <category>General</category>
         <pubDate>Thu, 14 Dec 2006 12:17:49 +0000</pubDate>
      </item>
            <item>
         <title>Anonymizing RFI attacks through Google</title>
         <description>Slashdotted today an experience to anonymizing RFI Attacks Through Google. An interesting approach that search engines should be aware, and if it could be done using Google crawler, it could be done also using any other spider : Noam Rathaus...</description>
         <link>http://security.phpmagazine.net/2006/11/anonymizing_rfi_attacks_throug.html</link>
         <guid>http://security.phpmagazine.net/2006/11/anonymizing_rfi_attacks_throug.html</guid>
         <category>Experience</category>
         <pubDate>Thu, 23 Nov 2006 20:30:00 +0000</pubDate>
      </item>
      
   </channel>
</rss>
