🦞🌯 Lobster Roll

Thread

Building Secure PHP Apps (buildsecurephpapps.com)

Stories related to "Building Secure PHP Apps" across the full archive.

Building Secure PHP Apps (buildsecurephpapps.com)
Building Searchable Encrypted Databases with PHP and SQL (paragonie.com)
The 2018 Guide to Building Secure PHP Software - Paragon Initiative Enterprises Blog (paragonie.com)
Troy Hunt: Everything you ever wanted to know about building a secure password reset feature (troyhunt.com)
I Forgot Your Password: Randomness Attacks Against PHP Applications (youtube.com)
Password Hashing in PHP, The Right Wayâ„¢ (longren.org)
Building a Better PHP with HHVM and Hack: Part 1 (ey.io)
Building a Better PHP — Part 2: Using HHVM (ey.io)
Building a Better PHP — Part 3: Getting Started with Hack (blog.engineyard.com)
Cracking PHP rand() (sjoerdlangkemper.nl)
HTTP_PROXY security vulnerability in Go, PHP, Python CGI environments (httpoxy.org)
How we broke PHP, hacked Pornhub and earned 20.000$ (evonide.com)
Detecting potentially malicious PHP code using checksums and heuristics on parse trees (blog.garage-coding.com)
SQL injections vulnerabilities in Stack Overflow PHP questions (laurent22.github.io)
Cryptographically Secure PHP Development (paragonie.com)
Mitigating PHP's long standing issue with OPCache leaking sensitive data (ma.ttias.be)
Guide to Automatic Security Updates For PHP Developers (paragonie.com)
sodium_compat: pure-PHP implementation of (most of) libsodium (github.com)
PHP 7.1.7 release (5 CVEs) (php.net)
Includes 5 CVEs fixed in mbstring module (oniguruma)
"Wherein existing techniques for building secure systems are examined and found wanting" (2000) (cypherpunks.to)
h/t @nickpsecurity for the fantastic find. From "The Design and Verification of a Cryptographic Security Architecture", found [here](https://researchspace.auckland.ac.nz/bitstream/handle/2292/2310/02whole.pdf?sequence=2).
Improving PHP extensions as a persistence method (x-c3ll.github.io)
RCE in PHP or how to bypass disable_functions in PHP installations (lab.wallarm.com)
If you installed PEAR PHP in the last 6 months, you may be infected (arstechnica.com)
DARPA is Building a $10mil, OSS, Secure, Voting System (motherboard.vice.com)
Data exfiltration with FPM servers (HHVM and rarely PHP) (openwall.com)
RCE through open PHP-FPM ports (openwall.com)
disable_functions Bypass Exploit in PHP 7.1 to PHP 7.3 (github.com)
Message Encryption in JavaScript and PHP with Libsodium (dev.to)
Announcing the Bytecode Alliance: Building a secure by default, composable future for WebAssembly (bytecodealliance.org)
Fuzzing PHP with Domato (blog.jmpesp.org)