New Consortium Aims to Set PHP Security Standards

NEW YORK — A group of international PHP experts, including one of the founders of PHP enterprise platform developer Zend Technologies, have banded together and formed a new conglomerate aimed at promoting secure programming practices.

The newly formed PHP Security Consortium, created in response to the recent Santy worm outbreak that besieged phpBB bulletin boards across the Internet, intends to publish a variety of articles focused on security proofing PHP code and also audit commonly used PHP-coded applications

“PHP application security is a topic of growing important,” said Andi Gutmans, a charter member of PHPSC and one of the co-founders of Zend, a company that specializes in offering enterprise-ready PHP solutions.

“The launch of the PHP Security Consortium is a landmark even for the PHP community, and because most web development technologies face similar security concerns, we believe that developers using other solutions can also benefit from our efforts,” Gutmana said.

The group’s creation was spurred by a bevy of recent high-profile security flaws found in third-party applications, which the group says has hurt the credibility of PHP and the growing PHP scripting community.

Commonly used for allowing web pages to interact with MySQL databases, the 10-year-old open-source scripting language has experienced explosive growth recently, with companies like Yahoo, Lycos, Disney and Deutsche Lufthansa adopting its use for everything from simple web access to complex electronic ticketing systems.

“As PHP has transitioned from personal project to enterprise application development, the need to educate the community about secure programming practices has risen,” said PHPSC founder Chris Shiflett.

Shiflett, who is also the creator of PHPCommunity.org and sits on the Zend PHP Advisory Board, said that one of the biggest problems for the PHP community is the perception that the language is unsuitable for secure web use.

“There’s this odd tendency in the PHP community to call everything PHP, even if it’s just a third-party application written in PHP,” Shiflett said. “We saw this happen with the phpBB issue, even though it had nothing to do with a security problem in PHP.”

According to Shiflett, the new group will also be involved in experimental research in order to develop standards of best practice for PHP application development in addition to publishing documentation and tools to help prospective PHP programmers.

“Because PHP has a very low barrier to entry, a lot of inexperienced developers are using it for their solutions,” Shiflett told eWeek. “They don’t tend to understand Web application security and they’re creating application with serious vulnerabilities.

“There is this urgent need to educate these developers and provide them with resources to get up to speed,” Shiflett said.

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Georgia Gov. Brian Kemp Signs Age Verification Bill Into Law

Republican Gov. Brian Kemp signed into law on Tuesday a bill that includes Georgia’s version of the age verification of adult content provisions being sponsored around the country by anti-porn religious conservative activists.

AEBN Publishes Popular Searches by Country for February, March

AEBN has released the popular searches from its straight and gay theaters in more than three dozen countries during February and March.

HardWerk Relaunches Through YourPaysitePartner

HardWerk.com has relaunched through YourPaysitePartner (YPP).

Aylo Asks Judge to Trim Sweeping GDP-Related Lawsuit

Aylo asked a California federal judge during a hearing on Monday to drop trafficking claims from a sweeping lawsuit brought by a former GirlsDoPorn model.

California Republicans, Democrats Team Up to Advance Age Verification for Porn

Both Republicans and Democrats in the California Assembly’s Privacy and Consumer Protection Committee voted last week to move forward a version of the age verification bills being sponsored around the country by anti-porn religious conservative activists.

Cosplayground Releases 'Furiosa XXX: A Porn Parody'

Cosplayground has released its seventh original production, “Furiosa XXX: A Porn Parody.”

Washington Post Spotlights ECP VP Solomon Friedman's Appearance at XBIZ LA

The Washington Post published this weekend a lengthy feature about Pornhub and Aylo, focusing on Ethical Capital Partners’ VP of Compliance Solomon Friedman’s keynote address and other appearances at XBIZ Los Angeles in January.

'Sex Workers Deserve Protections': Congressional Candidate Joe Cohn Reaches Out to Adult Community

Veteran civil rights attorney Joe Cohn, who is currently running in a New Jersey Democratic primary for a seat in the U.S. House of Representatives, says he is reaching out to the adult community to champion an inclusive approach to civil liberties that encompasses all sex workers and adult businesses.

Mile High Unveils New Unscripted Studio 'Sex on Sight'

Mile High Media has launched a new unscripted-content studio, Sex on Sight.

Belgian Producer Dennis Black Magic Sentenced to 7 Years for Rape, CSAM

Belgian adult producer and director Dennis Black Magic has been sentenced to seven years in prison and a $4,000 fine for the rape of eight models and distribution of CSAM.

Show More