The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

Comments

Posted by Sicurezza, ICT ed altro » Blog Archive &raqu
on Tuesday, January 16, 2007 at 10:53 AM

[...] Anche Wordpress 2.0.6 è (già) vulnerabile. Questo post del Cerias discute la questione, e mette in evidenza come la “sicurezza multilivello” sia necessaria proprio per limitare le conseguenze di  una vulnerabilità di uno dei tanti componenti di un sito/sistema/sistema informativo. [...]

Posted by PHP Devils » As if we needed more evidence t
on Sunday, March 4, 2007 at 02:26 PM

[...] Небольшая заметка о вреде включенных register_globals. For the past few years, PHP security experts have been pounding on the heads of sysadmins to turn off register_globals. While default installs of PHP turn it off, some popular web apps (especially older versions) insist on using it, so some webhost sysadmins will turn it on, presumably to make things go smoothly for their customers. Oops! Web app security (and any security, for that matter) must be multilayered: on the hardware level, on the server daemon level, on the language environment level, and on the code level. [...]

Leave a comment

Commenting is not available in this section entry.