Tag: security
PHP Vulnerabilities Announced
Just saw the announcement on Slashdot by the Hardened-PHP Project. The vulnerabilities include pack(), unpack(), safe_mode_exec_dir bypass in multithreaded PHP, realpath() and unserialize().
Posted: December 17th, 2004 under PHP.
Tags: PHP, security
Comments: none
Masquerade PHP as ASP
While I'm not generally someone to advocate Security through Obscurity, I do believe that it helps to make it harder for an attackers, because if they don't know what you're using, they may follow the wrong path (trying out hacking tools geared towards IIS on Apache, or believing you're running Apache when you're using thttpd) […]
Posted: November 15th, 2004 under PHP.
Tags: asp, extension, obscurity, PHP, security
Comments: none
Primer on SSH and SCP
Hardly anyone uses telnet to log into their UNIX shell anymore. And with good reason; the idea of having your password transmitted in clear text (i.e. unencrypted), thus easily obtained by nosey people equipped with the proper sniffing tools, just isn't all that appealing. The replacement for telnet is SSH, which stands for SecureSHell and […]
Posted: November 13th, 2004 under Software & Tools.
Tags: putty, scp, security, ssh
Comments: none
Firefox 1.0 released
Time to upgrade, folks. I'm currently still using Firefox 0.9.3, and it's proven itself to be an excellent replacement for Microsoft Internet Explorer.
Posted: November 12th, 2004 under Software & Tools.
Tags: browser, firefox, security, web
Comments: none