Jump to content

"Month of PHP bugs" initiative


rudy507

Recommended Posts

Hey guys,

I'm wondering how many of you are aware of this, and what you are thinking about doing with your code as a result. What security measures are you going to take, etc...? I'd also be interested in hearing more about this if anyone has more information. I was first told about this earlier today by our main PHP developer here at the school I attend (I'm a sophomore in college right now).

 

This is important stuff to be aware, so if this is the first time you've heard about it, make sure to read below, and follow the link, and do your own research. Security is important, friends.

 

Here's what I read on Slashdot:

 

"Stefan Esser is the founder of both the Hardened-PHP Project and the PHP Security Response Team (which he recently left). During an interview with SecurityFocus he announced the upcoming Month of PHP bugs initiative in March."

 

We will disclose different types of bugs' date=' mainly buffer overflows or double free (/destruction) vulnerabilities, some only local, but some remotely triggerable... Additionally there are some trivial bypass vulnerabilities in PHP's own protection features... As a vulnerability reporter you feel kinda puzzled how people among the PHP Security Response Team can claim in public that they do not know about any security vulnerability in PHP, when you disclosed about 20 holes to them in the two weeks before. At this point you stop bothering whether anyone considers the disclosure of unreported vulnerabilities unethical. Additionally a few of the reported bugs have been known for years among the PHP developers and will most probably never be fixed. In total we have more than 31 bugs to disclose, and therefore there will be days when more than one vulnerability will be disclosed.[/quote']

 

Source: http://developers.slashdot.org/article.pl?sid=07/02/20/0144218&from=rss

 

- David

Link to comment
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.