A group of researchers from MIT, Stanford and Syracuse have developed a new program, named “Ardilla”, which can analyze PHP code for Cross-Site Scripting (XSS) and SQL injection attack vulnerabilities.
Rather than just static analysis, this program actually traces the data through the software to determine whether the threat is real. This decreases false-positives significantly, compared to simple static analysis.
Here’s the technical paper for all us serious geeks…
I just got this beauty running Saturday night. It’s been a bit of a project… Cutting out rusted patches of the frame and welding in replacements, replacing the entire braking system, and rebuilding the front hubs.
Here’s a video that my wife, kids and I shot as we fired the engine up for the first time since late 2005. That was a good night!!!