<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PHPIDS &#8211; Security Layer &amp; Intrusion Detection for PHP Based Web Applications</title>
	<atom:link href="http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Sun, 08 Nov 2009 07:15:43 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: zupakomputer</title>
		<link>http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112464</link>
		<dc:creator>zupakomputer</dc:creator>
		<pubDate>Mon, 18 Feb 2008 23:01:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112464</guid>
		<description>One way to stay secure and not use any protection of course is to not advertise your sites and not have any keywords in them, block robots, and so forth; and also do all your own websurfs from a completely other machine with no details of the Siren computer refered to.</description>
		<content:encoded><![CDATA[<p>One way to stay secure and not use any protection of course is to not advertise your sites and not have any keywords in them, block robots, and so forth; and also do all your own websurfs from a completely other machine with no details of the Siren computer refered to.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pantagruel</title>
		<link>http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112462</link>
		<dc:creator>Pantagruel</dc:creator>
		<pubDate>Mon, 18 Feb 2008 22:50:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112462</guid>
		<description>@anonymous

Humor us, share the url/IP. There will be enough people about to point out why certain safety measures can be very helpfull. Just because your box, to your knowledge, hasn&#039;t been p0wned doesn&#039;t mean it won&#039;t be p0wned some time soon (or is under p0wnage right now).
In general the rule applies, the better you can test the perimeter security of your server, the fewer the amount of possible holes and the smaller the chance of being hacked/compromised.</description>
		<content:encoded><![CDATA[<p>@anonymous</p>
<p>Humor us, share the url/IP. There will be enough people about to point out why certain safety measures can be very helpfull. Just because your box, to your knowledge, hasn&#8217;t been p0wned doesn&#8217;t mean it won&#8217;t be p0wned some time soon (or is under p0wnage right now).<br />
In general the rule applies, the better you can test the perimeter security of your server, the fewer the amount of possible holes and the smaller the chance of being hacked/compromised.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zupakomputer</title>
		<link>http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112450</link>
		<dc:creator>zupakomputer</dc:creator>
		<pubDate>Mon, 18 Feb 2008 22:01:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112450</guid>
		<description>Hey, that&#039;s an info-gathering attempt on the slow-witted - claiming your web servers never been hacked and it&#039;s there, naked, waiting.....</description>
		<content:encoded><![CDATA[<p>Hey, that&#8217;s an info-gathering attempt on the slow-witted &#8211; claiming your web servers never been hacked and it&#8217;s there, naked, waiting&#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darknet</title>
		<link>http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112251</link>
		<dc:creator>Darknet</dc:creator>
		<pubDate>Mon, 18 Feb 2008 08:30:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112251</guid>
		<description>&lt;strong&gt;anonymous:&lt;/strong&gt; I never implied YOU needed it, nor did I say I needed it but does that means it&#039;s not required? I have a feeling you are young. If you&#039;ve ever worked on a reasonably complex problem (more than 100k lines of code) you would know mistakes happen, multiple people are working on the same thing and you need multiple layers of defence (AV/Firewall/Reverse Proxy/IDS/Application Layer Protection etc.).  And this tool in particular is an IDS not an IPS anyway so it doesn&#039;t protect you from anything, it just tells you what people are trying to do. The first step of being secure is understanding the threat :)</description>
		<content:encoded><![CDATA[<p><strong>anonymous:</strong> I never implied YOU needed it, nor did I say I needed it but does that means it&#8217;s not required? I have a feeling you are young. If you&#8217;ve ever worked on a reasonably complex problem (more than 100k lines of code) you would know mistakes happen, multiple people are working on the same thing and you need multiple layers of defence (AV/Firewall/Reverse Proxy/IDS/Application Layer Protection etc.).  And this tool in particular is an IDS not an IPS anyway so it doesn&#8217;t protect you from anything, it just tells you what people are trying to do. The first step of being secure is understanding the threat <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anonymous</title>
		<link>http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112132</link>
		<dc:creator>anonymous</dc:creator>
		<pubDate>Mon, 18 Feb 2008 00:43:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112132</guid>
		<description>@Darknet
My box runs neither a firewall, anti-virus or some sort of intrusion detection. And it has never been compromised in its 4 years of uptime. On average, it serves about 1400 HTTP requests daily.

I can agree that you may need extra protection in case you do not have the experience, but personally I would never run such an injection detection system on anything. I think it will only give the programmer a false sense of security, which will mosy likely result in other security checks beeing ignored.</description>
		<content:encoded><![CDATA[<p>@Darknet<br />
My box runs neither a firewall, anti-virus or some sort of intrusion detection. And it has never been compromised in its 4 years of uptime. On average, it serves about 1400 HTTP requests daily.</p>
<p>I can agree that you may need extra protection in case you do not have the experience, but personally I would never run such an injection detection system on anything. I think it will only give the programmer a false sense of security, which will mosy likely result in other security checks beeing ignored.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eM3rC</title>
		<link>http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112108</link>
		<dc:creator>eM3rC</dc:creator>
		<pubDate>Sun, 17 Feb 2008 22:38:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112108</guid>
		<description>@zupakomputer
Couldn&#039;t be more true. There will always be a weakness no matter what you do.

@Darknet
Lets do all of that and rid the world of disease and hunger!</description>
		<content:encoded><![CDATA[<p>@zupakomputer<br />
Couldn&#8217;t be more true. There will always be a weakness no matter what you do.</p>
<p>@Darknet<br />
Lets do all of that and rid the world of disease and hunger!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darknet</title>
		<link>http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112090</link>
		<dc:creator>Darknet</dc:creator>
		<pubDate>Sun, 17 Feb 2008 20:15:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112090</guid>
		<description>According to the wisdom of &#039;anonymous&#039; we wouldn&#039;t need anti-virus, intrusion detection, firewalls....hell let&#039;s just get rid of the whole security industry and simply ask everyone to code properly!</description>
		<content:encoded><![CDATA[<p>According to the wisdom of &#8216;anonymous&#8217; we wouldn&#8217;t need anti-virus, intrusion detection, firewalls&#8230;.hell let&#8217;s just get rid of the whole security industry and simply ask everyone to code properly!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zupakomputer</title>
		<link>http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112085</link>
		<dc:creator>zupakomputer</dc:creator>
		<pubDate>Sun, 17 Feb 2008 19:06:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-112085</guid>
		<description>That&#039;s the thing: no matter how well you know any language or instruction set, chances are someone else will know more, and someones else that know less will have cracking tools that can exploit whatever you wrote.
That&#039;s likely true even if you wrote the language itself - there&#039;ll be some machine code or assembley-based way of altering it.</description>
		<content:encoded><![CDATA[<p>That&#8217;s the thing: no matter how well you know any language or instruction set, chances are someone else will know more, and someones else that know less will have cracking tools that can exploit whatever you wrote.<br />
That&#8217;s likely true even if you wrote the language itself &#8211; there&#8217;ll be some machine code or assembley-based way of altering it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eM3rC</title>
		<link>http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-111937</link>
		<dc:creator>eM3rC</dc:creator>
		<pubDate>Sat, 16 Feb 2008 20:51:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-111937</guid>
		<description>Its always good to keep the code as simple and secure as possible but there&#039;s one things that is always true no matter what code it is. There will always be mistakes. Unless you have decades of experience for programming php securely it wont hurt to add more stuff. There are also some unknown techniques for hacking which you may not be aware of when you write the code.

One can never be to safe.</description>
		<content:encoded><![CDATA[<p>Its always good to keep the code as simple and secure as possible but there&#8217;s one things that is always true no matter what code it is. There will always be mistakes. Unless you have decades of experience for programming php securely it wont hurt to add more stuff. There are also some unknown techniques for hacking which you may not be aware of when you write the code.</p>
<p>One can never be to safe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anonymous</title>
		<link>http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-111924</link>
		<dc:creator>anonymous</dc:creator>
		<pubDate>Sat, 16 Feb 2008 19:04:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/02/phpids-security-layer-intrusion-detection-for-php-based-web-applications/#comment-111924</guid>
		<description>I don&#039;t get the point of using such a packet. Why not just go to the root of the problem and make your code secure in the first place?

I believe the more code there is, the more insecure your application will be. I always try to keep my code as simple as possible.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t get the point of using such a packet. Why not just go to the root of the problem and make your code secure in the first place?</p>
<p>I believe the more code there is, the more insecure your application will be. I always try to keep my code as simple as possible.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
