Feeds

Month of PHP bugs project launches

Script down to the core

Internet Security Threat Report 2014

Security researchers have begun a month-long project to highlight security flaws in PHP, the popular scripting language.

The "Month of PHP Bugs", which began last Thursday, promises a bug a day for the month of March from the folks behind the Hardened-PHP Project.

Unlike the earlier Month of Browser Bugs and Month of Apple Bugs projects, which inspired the PHP initiative, the Month of PHP bugs will feature both old and new bugs as part of the overall goal of raising awareness about PHP-related security issues. The project will focus on security flaws involving the PHP core, not programming errors that might result in insecure applications.

Eleven bugs have been detailed thus far as part of the project, which aims to shake up the way bugs in the scripting language are handled. The bugs involve a range of flaws of varying seriousness (from simple denial of service to remote exploitation) along with proof of concept exploit code, in most cases.

"This initiative is an effort to improve the security of PHP," Stefan Esser, a noted PHP security expert explains. "During March 2007 old and new security vulnerabilities in the Zend Engine, the PHP core and the PHP extensions will be disclosed on a day by day basis. We will also point out necessary changes in the current vulnerability management process used by the PHP Security Response Team." ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
BlackEnergy crimeware coursing through US control systems
US CERT says three flavours of control kit are under attack
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
New hybrid storage solutions
Tackling data challenges through emerging hybrid storage solutions that enable optimum database performance whilst managing costs and increasingly large data stores.
Getting ahead of the compliance curve
Learn about new services that make it easy to discover and manage certificates across the enterprise and how to get ahead of the compliance curve.