PHP Security Checker

We did a post on ten security checks for PHP, and pointed to a PHP security guide as well. On a more recent, related note, you might want to take a look at Rkrishardy.com regarding researchers from MIT, Stanford and Syracuse having developed “Ardilla”, which analyzes PHP code for XSS (Cross-Site Scripting) and SQL injection attack vulnerabilities.
Derived from a modified version of the Zend Interpreter, from work done at IBM, Ardilla can’t be released as open source because of licensing issues.

One Response to “PHP Security Checker”

  1. PRINCE2 training said on June 22nd, 2009 at 5:04 am

    Thanks for the info, I am studying PHP at the moment.

Zen-To-Done