EPISODE · Dec 28, 2008 · 1H
Vulnerability discovery in encrypted closed source PHP applications (25c3)
from Chaos Computer Club - 25C3: nothing to hide (ogg) · host Stefan Esser
Security audits of PHP applications are usually performed on a source code basis. However sometimes vendors protect their source code by encrypting their applications with runtime (bytecode-)encryptors. When these tools are used source code analysis is no longer possible and because these tools change how PHP works internally, several greybox security scanning/fuzzing techniques relying on hooks fail, too. about this event: http://events.ccc.de/congress/2008/Fahrplan/events/2678.en.html
What this episode covers
Security audits of PHP applications are usually performed on a source code basis. However sometimes vendors protect their source code by encrypting their applications with runtime (bytecode-)encryptors. When these tools are used source code analysis is no longer possible and because these tools change how PHP works internally, several greybox security scanning/fuzzing techniques relying on hooks fail, too. about this event: http://events.ccc.de/congress/2008/Fahrplan/events/2678.en.html
NOW PLAYING
Vulnerability discovery in encrypted closed source PHP applications (25c3)
No transcript for this episode yet
Similar Episodes
Mar 26, 2026 ·1m
Mar 19, 2026 ·34m
Feb 18, 2026 ·11m
Feb 11, 2026 ·45m