|
|
||||||
|
||||||
| Index Link To US Private Messages Archive FAQ RSS | ||||||
| Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help. |
Share Thread: & Tags
|
||||
|
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
||||
|
It did not appear as though anything quite like it existed, so I threw together a PHP security audit script.
Uploaded to your webserver, the script will check known PHP vulnerabilities and provide some general recommendations for securing your PHP installation. It's still a bit rough / paranoid, though I plan to add vulnerability-specific recommendations and some filters to determine the depth of vulnerability checking in the next revision. Informed PHP security suggestions (and general usability suggestions) welcomed.
__________________
Dan LeFree | Product Manager (Linux VPS Hosting) | Owner/Operator (Web development, marketing) |
|
||||
|
Thank you. The code is downloaded. I will test it when I have free time.
Some fast observations / questions:
|
|
||||
|
Quote:
It is also worth noting that PHP 6.0 does not support "safe mode" (reference), so I have included all functions which safe mode has historically restricted within the script. Quote:
Apache override files may load additional directives - those directives will be evaluated as they occur (I am not aware of a good way to distinguish between directive evaluation from within the script, though I will take into account the options which shared hosting users may have if Apache's AllowOverride setting is enabled and PHP is compiled as an Apache module). The audit script may be used with any webserver installation - while it will also run under a CLI installation there really isn't much of a need (if you're running PHP-CLI it is likely that you are primarily concerned with functionality over security). Thank you for the preliminary suggestions - I'll take a look at adding some additional instructions to the script (and please do let me know what you think after you've had a chance to run it).
__________________
Dan LeFree | Product Manager (Linux VPS Hosting) | Owner/Operator (Web development, marketing) |
|
||||
|
Quote:
PHP-Security-Audit.com is now online with a few updates to the script
__________________
Dan LeFree | Product Manager (Linux VPS Hosting) | Owner/Operator (Web development, marketing) |
|
|||
|
Thanks so much for your hard work. I have always had concerns about my websites security and have wished for an easy tool to check things. I agree that you should market this tool. It looks like a winner.
|
![]() |
|
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Struggling with audit trail | bizgen | Database Discussion Forum | 2 | 01-16-2009 07:13 PM |
| Need to audit security in Cisco APs? | WiFi-Owl | Internet Security Discussion Forum | 0 | 03-16-2007 03:58 AM |
| Enhance pay-per-click audit | iowasmiles | Search Engine Optimization Forum | 1 | 09-21-2004 08:20 PM |
| cardsremembered.com - SEO Review/Audit | goervin | Submit Your Site For Review | 2 | 07-25-2004 05:15 PM |
| Link Audit software? | rcmedia2004 | Google Discussion Forum | 0 | 06-17-2004 02:21 AM |
|
WebProWorld |
Advertise |
Contact Us |
About |
Forum Rules |
MVP's |
Archive |
Newsletter Archive |
Top |
WebProNews
WebProWorld is an iEntry, Inc. ® site - © 2009 All Rights Reserved Privacy Policy and Legal iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509 |