Re: PHP security analysis



You may want to look into Fortify $ource Code Analyzer v5.x - supports PHP

Not cheap, don't know of any free code scanners

On Fri, May 9, 2008 at 5:35 AM, Umut Arus <umuta@xxxxxxxxxxxxxxx> wrote:
Hi,

I'm looking for the best web application analysis which is the tool
especially PHP. I want to analyse the written PHP codes for security holes.
It is not important the way of scanning. It may be a command tool or URL
scanning. It should be a free or one time tool.

Which tool gives the most detailed information?

Regards,

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: Hack attempt
    ... It is a feature in PHP which you should ... This is a common web apps vulnerabilites. ... The host should be restricted to the only connections it is supposed ... In this case, a proper network filtering ...
    (Focus-Linux)
  • Re: Compiling PHP and/or any PHP Extension on VMS
    ... technology by managers who do not have a vision longer than next month is ... Some of those freely available PHP apps are very feature rich. ... "poor code quality => likely that there exists SQL injection ... web apps. ...
    (comp.os.vms)
  • Re: PHP or COLDFUSION
    ... >>I didn't say that PHP craps all over ASP.NET in every way. ... > PHP might have more functionality but .NET is geared towars Windows only as ... This is where it is futile trying to debate a language vs a framework. ... lot of people (who don't know much about modern web apps and XML/XSLT), ...
    (comp.lang.php)
  • Re: Pascal Server Page
    ... desktop apps, but prefer PHP for web apps. ... varaiable interpolation in strings which makes code much ... in web apps, this is a very significant advantage. ...
    (borland.public.delphi.non-technical)
  • How should I start?
    ... i have many years experience with most flavors of C, perl, php, ... want to develop stand-alone applications as well as web apps, ...
    (comp.lang.java.programmer)