Posts in PHP

Tuesday, October 24, 2006

New PHPSecInfo build out (20061023; v0.1.1)

This version fixes the errant Notices we were getting, makes it easier to extract test data for your own nefarious purposes, and fixes a bug with the curl file protocol test on PHP4. The latter unfortunately just skips the test on PHP4 because I’m not sure how to do the check; suggestions are welcome.

Download: http://phpsec.org/projects/phpsecinfo/phpsecinfo.zip

Docs: http://phpsec.org/projects/phpsecinfo/docs/

What’s new: v0.1.1 - Added PhpSecInfo::getOutput(), PhpSecInfo::loadAndRun() and PhpSecInfo::getResultsAsArray() methods - Modified PhpSecInfo::runTests() to fix undefined offsent notices - Modified PhpSecInfo_Test::setMessageForResult() to fix undefined offset notices - Modified PhpSecInfo_Test_Curl_File_Support to skip if PHP version is < 5 (detection of file protocol support relies on PHP5 version of curl_version)

Posted in PHPSecInfo, InfoSec, PHP by funkatron on 10/24 at 11:14 AM
(0) CommentsPost a comment

Saturday, October 21, 2006

Interview at Zend Developer Zone

I decided to not be all self-deprecating as I usually am with things like this, and admit that I’m really happy and proud to say that I was interviewed by Cal Evans for the Zend Developer Zone.

I guess the first question that comes to my mind is “Why did you build this?”
I built it because there was no good way to audit the security settings in your PHP.INI or your PHP environment. The average PHP user I feel is someone who can use an installer to install scripts on their server, get them running and do a little customization or hack up some code but they are not educated developers. These users have no easy way to check how secure their environment is. So I wrote PHPSecInfo to give these uses something easy to run and present the information in a format they are already familiar with.

Read the rest »

Posted in General, PHPSecInfo, PHP by funkatron on 10/21 at 08:27 PM
(0) CommentsPost a comment

Friday, October 20, 2006

PHPSecInfo Launched; Celebrity Status Imminent

So we finally went public with PHPSecInfo as an official project of the PHP Security Consortium.

http://phpsec.org/about/news/20oct2006.html

http://phpsec.org/projects/phpsecinfo/

http://phpdeveloper.org/news/6543

I just was interviewed by Cal Evans for the Zend Developer Zone, which was pretty cool — it was nice to talk to him again. He said the story should be posted sometime this weekend or Monday.

Posted in General, PHPSecInfo, PHP by funkatron on 10/20 at 02:43 PM
(1) CommentsPost a comment

Tuesday, June 27, 2006

OSCON 2006

So who’s going to OSCON 2006? I am, and if you are too, drop me a line so we can meet up. I’m also going to be “moderating” a PHP Security BOF meet, so if you have some interest in PHP Security or secure web dev in general, come by and participate in the chaos.

If you’re planning on going, make sure to check out the official wiki and the OSCamp wiki.

Posted in Development, InfoSec, The Web Problem, PHP by funkatron on 06/27 at 09:03 AM
(0) CommentsPost a comment

Tuesday, June 06, 2006

OSCON 2006: Portland Shall Burn

I will be attending OSCON in Portland, OR. I’ll be flying in the evening of July 25th, and leaving the morning of July 29th. I’m rather excited, because this time I will actually know some of the people attending/speaking at the event, and I think there will be a lot of opportunities to meet cool people, trade ideas, and talk to folks about CERIAS and the PHP Security Consortium.  If you’re going to OSCON and want to meet up, let me know!

Posted in General, Development, InfoSec, The Web Problem, PHP by funkatron on 06/06 at 12:44 PM
(0) CommentsPost a comment
Page 13 of 18 pages « First  <  11 12 13 14 15 >  Last »