69

Security audits as integral part of php application development (version 2012-02)

Embed Size (px)

DESCRIPTION

More often than not, web applications start off as a bright idea, which is then brought into realization at a fast and furious pace, with little eye for anything but result. Once all envisioned functionality is incorporated in the design and the project is launched, developers will be assigned to the next project. Notwithstanding a few bug fixes, the final - yet essential - step of software development is more often than not, omitted: the security audit. Despite the fact that these checks are regarded as tedious and superfluous, practice shows that it is time well spent: numerous, often severe vulnerabilities come to light. In his presentation, Sijmen Ruwhof will detail how to incorporate security checks into the software development process. He will also step through the implementation, and caveats of a security audit. Ruwhof works for Secundity as a security analyst specialized in PHP audits.

Citation preview

Page 1: Security audits as integral part of php application development (version 2012-02)
Page 2: Security audits as integral part of php application development (version 2012-02)
Page 3: Security audits as integral part of php application development (version 2012-02)
Page 4: Security audits as integral part of php application development (version 2012-02)
Page 5: Security audits as integral part of php application development (version 2012-02)
Page 6: Security audits as integral part of php application development (version 2012-02)
Page 7: Security audits as integral part of php application development (version 2012-02)
Page 8: Security audits as integral part of php application development (version 2012-02)
Page 9: Security audits as integral part of php application development (version 2012-02)
Page 10: Security audits as integral part of php application development (version 2012-02)
Page 11: Security audits as integral part of php application development (version 2012-02)
Page 12: Security audits as integral part of php application development (version 2012-02)
Page 13: Security audits as integral part of php application development (version 2012-02)
Page 14: Security audits as integral part of php application development (version 2012-02)
Page 15: Security audits as integral part of php application development (version 2012-02)
Page 16: Security audits as integral part of php application development (version 2012-02)
Page 17: Security audits as integral part of php application development (version 2012-02)
Page 18: Security audits as integral part of php application development (version 2012-02)
Page 19: Security audits as integral part of php application development (version 2012-02)
Page 20: Security audits as integral part of php application development (version 2012-02)
Page 21: Security audits as integral part of php application development (version 2012-02)
Page 22: Security audits as integral part of php application development (version 2012-02)
Page 23: Security audits as integral part of php application development (version 2012-02)
Page 24: Security audits as integral part of php application development (version 2012-02)
Page 25: Security audits as integral part of php application development (version 2012-02)
Page 26: Security audits as integral part of php application development (version 2012-02)
Page 27: Security audits as integral part of php application development (version 2012-02)
Page 28: Security audits as integral part of php application development (version 2012-02)
Page 29: Security audits as integral part of php application development (version 2012-02)
Page 30: Security audits as integral part of php application development (version 2012-02)
Page 31: Security audits as integral part of php application development (version 2012-02)
Page 32: Security audits as integral part of php application development (version 2012-02)
Page 33: Security audits as integral part of php application development (version 2012-02)
Page 34: Security audits as integral part of php application development (version 2012-02)
Page 35: Security audits as integral part of php application development (version 2012-02)
Page 36: Security audits as integral part of php application development (version 2012-02)
Page 37: Security audits as integral part of php application development (version 2012-02)
Page 38: Security audits as integral part of php application development (version 2012-02)
Page 39: Security audits as integral part of php application development (version 2012-02)
Page 40: Security audits as integral part of php application development (version 2012-02)
Page 41: Security audits as integral part of php application development (version 2012-02)
Page 42: Security audits as integral part of php application development (version 2012-02)
Page 43: Security audits as integral part of php application development (version 2012-02)
Page 44: Security audits as integral part of php application development (version 2012-02)
Page 45: Security audits as integral part of php application development (version 2012-02)
Page 46: Security audits as integral part of php application development (version 2012-02)
Page 47: Security audits as integral part of php application development (version 2012-02)
Page 48: Security audits as integral part of php application development (version 2012-02)
Page 49: Security audits as integral part of php application development (version 2012-02)
Page 50: Security audits as integral part of php application development (version 2012-02)
Page 51: Security audits as integral part of php application development (version 2012-02)
Page 52: Security audits as integral part of php application development (version 2012-02)
Page 53: Security audits as integral part of php application development (version 2012-02)
Page 54: Security audits as integral part of php application development (version 2012-02)
Page 55: Security audits as integral part of php application development (version 2012-02)
Page 56: Security audits as integral part of php application development (version 2012-02)
Page 57: Security audits as integral part of php application development (version 2012-02)
Page 58: Security audits as integral part of php application development (version 2012-02)
Page 59: Security audits as integral part of php application development (version 2012-02)
Page 60: Security audits as integral part of php application development (version 2012-02)
Page 61: Security audits as integral part of php application development (version 2012-02)
Page 62: Security audits as integral part of php application development (version 2012-02)
Page 63: Security audits as integral part of php application development (version 2012-02)
Page 64: Security audits as integral part of php application development (version 2012-02)
Page 65: Security audits as integral part of php application development (version 2012-02)
Page 66: Security audits as integral part of php application development (version 2012-02)
Page 67: Security audits as integral part of php application development (version 2012-02)
Page 68: Security audits as integral part of php application development (version 2012-02)
Page 69: Security audits as integral part of php application development (version 2012-02)