Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×
Security

New PHP Interpreter Finds XSS, Injection Holes 66

rkrishardy writes "A group of researchers from MIT, Stanford, and Syracuse has developed a new program, named 'Ardilla,' which can analyze PHP code for cross-site scripting (XSS) and SQL injection attack vulnerabilities. (Here is the paper, in PDF, and a table of results from scanning six PHP applications.) Ardilla uses a modified Zend interpreter to analyze the code, trace the data, and determine whether the threat is real or not, significantly decreasing false positives." Unfortunately, license issues prevent the tool in its current form from being released as open source.

Comment Re:An echo chamber... (Score 1) 409

Oops, try that again with a real list (and a slight rewrite) ...

No, it's not that at all. All they're trying to claim is that you can't sue them for copyright infringement for storing your content after you delete your account - i.e. it's more

  1. Write your content on Facebook.
  2. Delete Facebook account.
  3. Publish dead-tree book of your content.
  4. Realise Facebook still has your content available to users (e.g. if you mailed it to your BFF).
  5. Sue Facebook for copyright infringement.
  6. Facebook tell you to get stuffed, because you agreed to licence it to them.

There's more of an issue when 4 is replaced by the following:

4a. Facebook publish a "best of Facebook posts" book, containing your content.

Comment Re:An echo chamber... (Score 1) 409

No, it's not that at all. All they're trying to claim is that you can't sue them for copyright infringement for storing your content after you delete your account - i.e. it's more 1. Write your content on Facebook. 2. Delete Facebook account. 3. Publish dead-tree book of your content. 4. Realise Facebook still has your content available to users (e.g. if you mailed it to your BFF). 5. Sue Facebook for copyright infringement. 6. Facebook tell you to get stuffed, because you agreed to licence it to them. The issue might more be what happens when 4 is replaced by the following: 4a. Facebook publish a "best of Facebook posts" book, containing your content.

Slashdot Top Deals

He has not acquired a fortune; the fortune has acquired him. -- Bion

Working...