Sektion Eins, die Firma ums Stefan Esser, ruft zum Month of PHP Security 2010 auf.
Es gibt einige Preise, unter anderem Freitickets zur Syscan , zu gewinnen.
Diese Themen werden zum Monat der PHP Sicherheit 2010 angenommen:
- New vulnerability in PHP [1]
(not simple safe_mode, open_basedir bypass vulnerabilities)
- New vulnerability in PHP related software [1]
(popular 3rd party PHP extensions/patches)
- Explain a single topic of PHP application security in detail
(such as guidelines on how to store passwords)
- Explain a complicated vulnerability in/attack against a PHP
widespread application [1]
- Explain a complicated topic of attacking PHP (e.g. explain how to
exploit heap overflows in PHP's heap implementation)
- Explain how to attack encrypted PHP applications
- Release of a new open source PHP security tool
- Other topics related to PHP or PHP application security
[1] Articles about new vulnerabilities should mention possible fixes or mitigations.