Slides from PHP Website Security Talk at RVASec

RVAsec LogoThis past weekend I had the honor of presenting some PHP security research I’ve been pulling together for some time now. The presentation was based on my AppSecDC PHPIDS talk however I emphasized overall PHP security more than PHPIDS. Here’s the title, abstract, and link to download the slides.  Thanks to @jkouns, @chrissullo, @hackrva and the rest of the @rvasec crew for running an awesome conference!

“PHP Website Security, Attack Analysis, & Mitigations”

PHP is a very powerful language for easily developing web applications however this convenience sometimes comes at the cost of security. Issues can arise from everything from language vulnerabilities and weak default settings to insecure coding practices and misconfigurations. This presentation plans to address many of these concerns by providing valuable lessons in the security of, attacks against, and management of PHP in your environment. The talk begins with an overview of PHP security, including it’s known issues and corresponding security enhancements the maintainers have incorporated over time. Beginning with a general discussion of PHPIDS and how it can be used as an event tracker, the presentation next provides a peak into some of the more interesting attacks against a security website as well as overall trends from two years in deployment. The talk closes with a strategy for analyzing the risks in your PHP environment and applying corresponding PHP and platform/network mitigations to minimize your attack surface.

Download the Slides

#####

If you were at RVAsec and got a chance to hear my talk … let me know what you thought! Today’s post pic is from richSEC.com. See ya!

6 comments for “Slides from PHP Website Security Talk at RVASec

  1. June 17, 2012 at 4:03 pm

    Slides from PHP Website Security Talk at RVASec: This past weekend I had the honor of presenting some PHP sec… http://t.co/nHve0npk

  2. June 17, 2012 at 4:14 pm

    BLOGGED: Slides from PHP Website Security Talk at RVASec http://t.co/6ZGc4Nc5

  3. June 17, 2012 at 5:39 pm

    This past weekend I had the honor of presenting some PHP security research I’ve been pulling together for some t… http://t.co/8oIYxB9W

  4. June 17, 2012 at 7:34 pm

    BLOGGED: Slides from PHP Website Security Talk at #RVASec http://t.co/gMaVPaSP //From earlier today.

  5. June 17, 2012 at 11:25 pm

    BLOGGED: Slides from PHP Website Security Talk at RVASec http://t.co/gMaVPaSP //In case U missed.

  6. July 5, 2012 at 7:09 pm

    rt [email protected]

    # Slides from PHP Website Security Talk at RVASec http://t.co/13G9tq8M http://t.co/wBH1TcOT

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.