YoVDO

Snuffleupagus - Killing Bugclasses in PHP 7, Virtual-Patching the Rest

Offered By: Cooper via YouTube

Tags

Hack.lu Courses Web Development Courses Application Security Courses Remote Code Execution Courses Authentication Bypass Courses

Course Description

Overview

Explore a conference talk on Snuffleupagus, an open-source PHP security module designed to address vulnerabilities in PHP 7 applications. Learn about its features for passively eliminating PHP-specific bug classes and implementing virtual-patching at the PHP level. Discover how this tool allows for precise, false-positive-free, and low-overhead vulnerability patching without modifying application code. Gain insights into PHP security, including topics such as disabling functions, filtering content, handling PHP eval, and addressing XML external entities. Understand the performance impact and benefits of using Snuffleupagus in secure web hosting environments.

Syllabus

Intro
What we already do
PHP
PHP Documentation
ThroughScene
Snuffleupagus
Babar
PHP eval
Disable function
Disable function call
Complex rules
Drop call to internalfunc
Filter unviable content
Code examples
PHP features
System function
Male
Roaming
Cookies
Documentation
Analyzing documentation
PHP special object
How we are killing it
XML external entities
Demos
Authentication bypass
Post variable
Remote code
Blacklisting
Deadening
Performance Impact
Sloppy Comparison
Release Party
PHP Energy
Reddit


Taught by

Cooper

Related Courses

Modern Pentest Tricks for Faster, Wider, Greater Engagements
Cooper via YouTube
Take Your Path Normalization Off and Pop 0days Out
Cooper via YouTube
Finding the Best TI Provider for a Specific Purpose
Cooper via YouTube
Make ARM Shellcode Great Again
Cooper via YouTube
Digital Safety for Politically Vulnerable Organizations
Cooper via YouTube