YoVDO

Security Module for PHP7 - Killing Bugclasses and Virtual-Patching the Rest

Offered By: 44CON Information Security Conference via YouTube

Tags

44CON Courses Web Development Courses Application Security Courses Vulnerability Management Courses

Course Description

Overview

Explore a conference talk from 44CON 2018 on developing Snuffleupagus, an open-source PHP security module designed to address vulnerabilities in PHP7 applications. Learn about passive bug class elimination, virtual-patching techniques, and how this module improves upon the aging Suhosin. Discover methods for implementing precise, false-positive-free, and low-overhead security measures without modifying application code. Gain insights into PHP-specific security challenges, remote administration, granular patching, and strategies for preventing common vulnerabilities like XSS and remote code execution. Understand the module's performance implications and future development plans, including workshop opportunities and documentation resources.

Syllabus

Intro
PHP internal code
Remote administration
elephant
chaching
granular patching
virtual machine
extra parameter
value stream
kill vulnerability
stealing XSS
cookies
unsterilized
remote code execution
remote boot
R documentation
Xxe
CV
Support values
File manipulation
bug tracker
comparison
PHP madness
No Passport
Strict Mode
ReadOnly Detection
Dump Rules
My sequel query
Performance
Going forward
Workshop
Documentation
PHP
Thank you


Taught by

44CON Information Security Conference

Related Courses

MongoDB for .NET Developers
MongoDB University
Web Application Development – Capstone Course
University of New Mexico via Coursera
Ciberseguridad: ataques y contramedidas
Universidad Rey Juan Carlos via Independent
Reliable Cloud Infrastructure: Design and Process auf Deutsch
Google Cloud via Coursera
Securing and Integrating Components of your Application 日本語版
Google Cloud via Coursera