|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Howto Find bugs? |
|
Posted: Wed Jan 26, 2005 4:37 am |
|
|
zer0-c00l |
Advanced user |
|
|
Joined: Jun 25, 2004 |
Posts: 72 |
Location: BRAZIL! |
|
|
|
|
|
|
Hi Everyone,
first: i dont speak english very well, so ignore errors :S
i am programmer, and i wanna do a program.. u put the .php file, and the program scan the bugs..
but, how a SQL INJECTION bug consists in PHP?
can u understand? what the scanner need to see, to know if its vulnerable or not?
thanks |
|
|
|
|
|
Re: Howto Find bugs? |
|
Posted: Wed Mar 02, 2005 1:30 pm |
|
|
LINUX |
Moderator |
|
|
Joined: May 24, 2004 |
Posts: 404 |
Location: Caiman |
|
|
|
|
|
|
zer0-c00l wrote: | Hi Everyone,
first: i dont speak english very well, so ignore errors :S
i am programmer, and i wanna do a program.. u put the .php file, and the program scan the bugs..
but, how a SQL INJECTION bug consists in PHP?
can u understand? what the scanner need to see, to know if its vulnerable or not?
thanks |
if you is developer here source code the first scanner for file inclusion,xss,fopen and other, this scanner is very good
source code:http://overdose.tcpteam.org/rpvs_src/ |
|
|
|
|
|
Re: Howto Find bugs? |
|
Posted: Thu Mar 03, 2005 7:43 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
Best scan is manual scanning
All those automated scanners are good, but there can be huge number
of software bugs, which can be discovered only manually.
zer0-c00l wrote: | Hi Everyone,
first: i dont speak english very well, so ignore errors :S
i am programmer, and i wanna do a program.. u put the .php file, and the program scan the bugs..
but, how a SQL INJECTION bug consists in PHP?
can u understand? what the scanner need to see, to know if its vulnerable or not?
thanks |
|
|
|
|
|
Posted: Fri Mar 04, 2005 1:19 am |
|
|
no0bz |
Regular user |
|
|
Joined: Aug 06, 2004 |
Posts: 5 |
Location: cordoba, argentina |
|
|
|
|
|
|
totaly whit u waraxe, the best way 2 find bugs is camparing testing, viewing all manually, in that way beside of all that we will see that eachtime is more easy and more easy... use your mind, dont be a scritpkiddie...xD[/code][/b] |
|
_________________ Try me... |
|
|
|
Posted: Fri Mar 04, 2005 11:43 am |
|
|
Zeelock |
Active user |
|
|
Joined: Jan 27, 2005 |
Posts: 29 |
Location: Where stars come out at night |
|
|
|
|
|
|
Really good is to use a debugger.
Using Zend is amazing what you can find... |
|
_________________ If it seems to be impossible, just step up your level! |
|
|
|
www.waraxe.us Forum Index -> Newbies corner
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|