Vulnerability discovery in encrypted closed source PHP applications (25c3)
An episode of the Chaos Computer Club - 25C3: nothing to hide (ogg) podcast, hosted by Stefan Esser, titled "Vulnerability discovery in encrypted closed source PHP applications (25c3)" was published on December 28, 2008 and runs 60 minutes.
December 28, 2008 ·60m · Chaos Computer Club - 25C3: nothing to hide (ogg)
Summary
Security audits of PHP applications are usually performed on a source code basis. However sometimes vendors protect their source code by encrypting their applications with runtime (bytecode-)encryptors. When these tools are used source code analysis is no longer possible and because these tools change how PHP works internally, several greybox security scanning/fuzzing techniques relying on hooks fail, too. about this event: http://events.ccc.de/congress/2008/Fahrplan/events/2678.en.html
Episode Description
Similar Episodes
Sep 24, 2025 ·8m
Dec 4, 2024 ·5m
Dec 4, 2024 ·16m
Nov 27, 2024 ·7m