Re: [PHP] PHP Application Vuln. Testing

2006-02-07 Thread Ligaya Turmelle
Have you looked over phpsec.org site? read over the security guide, and the various articles? Jason Gerfen wrote: Richard Davey wrote: On 7 Feb 2006, at 16:54, Jason Gerfen wrote: Is there any product available, commercial or free which performs source code auditing which *specificly sear

Re: [PHP] PHP Application Vuln. Testing

2006-02-07 Thread Matt Stone
- Original Message - From: "Jason Gerfen" <[EMAIL PROTECTED]> To: "PHP General (E-mail)" Sent: Tuesday, February 07, 2006 4:54 PM Subject: [PHP] PHP Application Vuln. Testing > > Is there any product available, commercial or free which performs source &

Re: [PHP] PHP Application Vuln. Testing

2006-02-07 Thread John Nichel
Jason Gerfen wrote: I have a question which as of yet I am unable to find any information about from googling. Lets say you have just written a fairly robust PHP/MySQL application and would like to put it on your production server. For reasons of clarification lets say this application handle

Re: [PHP] PHP Application Vuln. Testing

2006-02-07 Thread Jason Gerfen
Richard Davey wrote: On 7 Feb 2006, at 16:54, Jason Gerfen wrote: Is there any product available, commercial or free which performs source code auditing which *specificly searches PHP code for SQL, XSS type of attacks or vulnerabilities? TIA. No. But there are people who can perform the

Re: [PHP] PHP Application Vuln. Testing

2006-02-07 Thread Richard Davey
On 7 Feb 2006, at 16:54, Jason Gerfen wrote: Is there any product available, commercial or free which performs source code auditing which *specificly searches PHP code for SQL, XSS type of attacks or vulnerabilities? TIA. No. But there are people who can perform the service for you (Brai

[PHP] PHP Application Vuln. Testing

2006-02-07 Thread Jason Gerfen
I have a question which as of yet I am unable to find any information about from googling. Lets say you have just written a fairly robust PHP/MySQL application and would like to put it on your production server. For reasons of clarification lets say this application handles sensitive customer