Log in
R. Kris Hardy Photo

R. Kris Hardy

June 19, 2009

MIT/Stanford/Syracuse Team Develop New PHP Intepreter-Based XSS and SQL Security Tester

Filed under: Development — Tags: , , , , — Kris @ 5:55 am

Ardilla PaperA group of researchers from MIT, Stanford and Syracuse have developed a new program, named “Ardilla”, which can analyze PHP code for Cross-Site Scripting (XSS) and SQL injection attack vulnerabilities.

Rather than just static analysis, this program actually traces the data through the software to determine whether the threat is real. This decreases false-positives significantly, compared to simple static analysis.

Here’s the technical paper for all us serious geeks…

(more… >>)

Technorati Tags: , , , ,


Powered by WordPress