<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Albert Fama &#187; resources</title>
	<atom:link href="http://albertfama.com/tag/resources/feed/" rel="self" type="application/rss+xml" />
	<link>http://albertfama.com</link>
	<description>Freelance Web Programmer - specializing in PHP &#38; MySQL</description>
	<lastBuildDate>Fri, 20 Nov 2009 16:06:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Security Resources</title>
		<link>http://albertfama.com/php/security-resources/</link>
		<comments>http://albertfama.com/php/security-resources/#comments</comments>
		<pubDate>Fri, 16 Nov 2007 14:17:01 +0000</pubDate>
		<dc:creator>Albert Fama</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[links]]></category>
		<category><![CDATA[resources]]></category>

		<guid isPermaLink="false">http://obnexus.net/?p=38</guid>
		<description><![CDATA[After posting Simple XSS Vulnerability according to my site stats, it seems there is a large number people interested in PHP security, more so than any other topic I have blogged about. Since I am no security expert I thought I would provide a few links to some quality resources on the net. One of [...]]]></description>
			<content:encoded><![CDATA[<p>After posting <a href="/?p=37" title="Obnexus: Simple XSS Vulnerability">Simple XSS Vulnerability</a> according to my site stats, it seems there is a large number people interested in PHP security, more so than any other topic I have blogged about. Since I am no security expert I thought I would provide a few links to some quality resources on the net.</p>
<p>One of the best resources is the <a href="http://phpsec.org/"  title="PHP Security Consortium">PHP Security Consortium</a>, where you can find the <a href="http://phpsec.org/projects/"  title="PHP Security Consortium: Projects">PHP Security Guide</a>. It is published in three different formats (HTML, PDF, DocBook Lite) and four different languages (English, French, Romanian, Serbian). They also publish their own <a href="http://phpsec.org/articles/"  title="PHP Security Consortium: Articles">articles</a> and have a links <a href="http://phpsec.org/library/"  title="PHP Security Consortium: Library">library</a> to numerous articles on other sites.</p>
<p>The founder of the PHP Security Consortium is <a href="http://shiflett.org/"  title="Chris Shiflett">Chris Shiflett</a>, who has published a few books (including <a href="http://phpsecurity.org/"  title="Essential PHP Security">Essential PHP Security</a>). He, of course, also has his own website where you will find the <a href="http://shiflett.org/blog"  title="PHP &#038; Web Application Security Blog">PHP &#038; Web Application Security Blog</a> along with numerous <a href="http://shiflett.org/articles"  title="shiflett.org: Articles">articles</a>. While gathering the links for this post, I found an excellent article about XSS (<a href="http://shiflett.org/articles/foiling-cross-site-attacks"  title="shiflett.org: Foiling Cross-Site Attacks">Foiling Cross-Site Attacks</a>).</p>
<p>Another well-known PHP security expert is <a href="http://ilia.ws/"  title="Ilia Alshanetsky">Ilia Alshanetsky</a>, creator of <a href="http://fudforum.org/forum/"  title="FUDforum">FUDforum</a>. He has published <a href="http://www.phparch.com/pgps" >php|architect&#8217;s Guide to PHP Security</a>, and runs his own <a href="http://ilia.ws/"  title="Ilia Alshanetsky">blog</a>.</p>
<p>If you haven&#8217;t yet heard about the <a href="http://www.hardened-php.net/"  title="Hardened-PHP Project">Hardened-PHP Project</a>, it is well worth checking out. There you will find <a href="http://www.hardened-php.net/suhosin.127.html"  title="Hardened-PHP Project: Suhosin">Suhosin</a>, an advanced protection system for PHP installations. Also the <a href="http://www.hardened-php.net/hardening_patch.14.html"  title="Hardened-PHP Project: Hardening patch">Hardening patch</a>, a patchset that adds security hardening features to PHP to protect your servers on the one hand against a number of well known problems in PHP applications and on the other hand against potential unknown vulnerabilities within those applications or the PHP core itself. This is also the team that brought us the <a href="http://php-security.org/"  title="Month of PHP Bugs">Month of PHP Bugs</a> in March &#8217;07.</p>
<p>An outspoken member of the Hardened-PHP Project is Stefan Esser, formerly a member of the php.net&#8217;s Security Response Team. Stefen Esser used to have the most active PHP security blog (<a href="http://blog.php-security.org/"  title="PHP Security Blog">PHP Security Blog</a>), but for unknown reasons the blog has not been updated for several months.</p>
<p>I know there are numerous other PHP security resources on the net, but I am hoping that these links will help get you started on finding quality PHP security resources. If anyone has other sources which you frequently use please post the URL in a comment.</p>

                            <div id="aspdf">
                                <a href="http://albertfama.com/wp-content/plugins/as-pdf/generate.php?post=38">
                                    <span>&nbsp;</span>
                                </a>
                            </div>
                        ]]></content:encoded>
			<wfw:commentRss>http://albertfama.com/php/security-resources/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
