<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Kaf</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Kaf"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Kaf"/>
		<updated>2026-04-23T13:22:30Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_PHP_Table_of_Contents&amp;diff=22384</id>
		<title>OWASP PHP Table of Contents</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_PHP_Table_of_Contents&amp;diff=22384"/>
				<updated>2007-10-12T20:22:36Z</updated>
		
		<summary type="html">&lt;p&gt;Kaf: New page: ==PHP Security for Architects== ==PHP Security for Developers==   ===Noteworthy Frameworks===&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==[[PHP Security for Architects]]==&lt;br /&gt;
==[[PHP Security for Developers]]==  &lt;br /&gt;
===Noteworthy Frameworks===&lt;/div&gt;</summary>
		<author><name>Kaf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_PHP_Project&amp;diff=22383</id>
		<title>Category:OWASP PHP Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_PHP_Project&amp;diff=22383"/>
				<updated>2007-10-12T19:34:34Z</updated>
		
		<summary type="html">&lt;p&gt;Kaf: /* PHP Security Overview */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==About==&lt;br /&gt;
&lt;br /&gt;
The OWASP PHP Project's goal is to enable PHP developers to build secure applications efficiently. See the [[OWASP PHP Project Roadmap]] for more information on our plans.&lt;br /&gt;
&lt;br /&gt;
==Joining the Project==&lt;br /&gt;
&lt;br /&gt;
The OWASP PHP project is in the process of being formed.  We are seeking a leader (or leaders) for the project develop the [[OWASP PHP Project Roadmap]] and identify the first tasks. If you're interested and could commit to 4-8 hours a week, please send an email describing your background to [mailto:owasp@owasp.org owasp@owasp.org].&lt;br /&gt;
&lt;br /&gt;
==PHP Security Overview==&lt;br /&gt;
&lt;br /&gt;
It is not easy to produce a PHP application without security vulnerabilities. Most application security [[:Category:Vulnerability|vulnerabilities]] apply to PHP applications just like other environments. &lt;br /&gt;
&lt;br /&gt;
The goals of this project are to provide information about building, configuring, deploying, operating, and maintaining secure PHP applications. We cover the following topics or pick a topic from the [[OWASP PHP Table of Contents]]&lt;br /&gt;
&lt;br /&gt;
; [[PHP Security for Architects]]&lt;br /&gt;
: Provides information about the design and architectural considerations for a PHP web application.  Common architectures such as MVC, Ajax, Web Services and PEAR / Zend Frameworks are discussed.&lt;br /&gt;
&lt;br /&gt;
; [[PHP Security for Developers]]&lt;br /&gt;
: This section covers dangerous calls and common vulnerabilities associated with them, such as system() exec(), eval() and so on. This section will also cover standard security mechanisms available in the standard language, such as cryptography, logging, encryption, and error handling. Securing elements of an application, such as controllers, business logic, and persistence layers will be covered. We'll discuss handling request parameters, encoding, injection, and more. &lt;br /&gt;
&lt;br /&gt;
; [[PHP Security for Deployers]]&lt;br /&gt;
: These articles cover topics specifically related to the PHP hosting environment. We discuss minimizing the attack surface, configuring error handlers, and performing hardening of PHP.&lt;br /&gt;
&lt;br /&gt;
==PHP Articles==&lt;br /&gt;
&lt;br /&gt;
* [[PHP Top 5]] - OWASP PHP Top 5&lt;br /&gt;
&lt;br /&gt;
[[Category:Language]]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP PHP Project]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Technology]]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Kaf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_PHP_Project&amp;diff=22382</id>
		<title>Category:OWASP PHP Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_PHP_Project&amp;diff=22382"/>
				<updated>2007-10-12T19:33:42Z</updated>
		
		<summary type="html">&lt;p&gt;Kaf: /* PHP Security Overview */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==About==&lt;br /&gt;
&lt;br /&gt;
The OWASP PHP Project's goal is to enable PHP developers to build secure applications efficiently. See the [[OWASP PHP Project Roadmap]] for more information on our plans.&lt;br /&gt;
&lt;br /&gt;
==Joining the Project==&lt;br /&gt;
&lt;br /&gt;
The OWASP PHP project is in the process of being formed.  We are seeking a leader (or leaders) for the project develop the [[OWASP PHP Project Roadmap]] and identify the first tasks. If you're interested and could commit to 4-8 hours a week, please send an email describing your background to [mailto:owasp@owasp.org owasp@owasp.org].&lt;br /&gt;
&lt;br /&gt;
==PHP Security Overview==&lt;br /&gt;
&lt;br /&gt;
It is not easy to produce a PHP application without security vulnerabilities. Most application security [[:Category:Vulnerability|vulnerabilities]] apply to PHP applications just like other environments. &lt;br /&gt;
&lt;br /&gt;
The goals of this project are to provide information about building, configuring, deploying, operating, and maintaining secure PHP applications. We cover the following topics or pick a topic from the OWASP PHP Table of Contents&lt;br /&gt;
&lt;br /&gt;
; [[PHP Security for Architects]]&lt;br /&gt;
: Provides information about the design and architectural considerations for a PHP web application.  Common architectures such as MVC, Ajax, Web Services and PEAR / Zend Frameworks are discussed.&lt;br /&gt;
&lt;br /&gt;
; [[PHP Security for Developers]]&lt;br /&gt;
: This section covers dangerous calls and common vulnerabilities associated with them, such as system() exec(), eval() and so on. This section will also cover standard security mechanisms available in the standard language, such as cryptography, logging, encryption, and error handling. Securing elements of an application, such as controllers, business logic, and persistence layers will be covered. We'll discuss handling request parameters, encoding, injection, and more. &lt;br /&gt;
&lt;br /&gt;
; [[PHP Security for Deployers]]&lt;br /&gt;
: These articles cover topics specifically related to the PHP hosting environment. We discuss minimizing the attack surface, configuring error handlers, and performing hardening of PHP.&lt;br /&gt;
&lt;br /&gt;
==PHP Articles==&lt;br /&gt;
&lt;br /&gt;
* [[PHP Top 5]] - OWASP PHP Top 5&lt;br /&gt;
&lt;br /&gt;
[[Category:Language]]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP PHP Project]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Technology]]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Kaf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_PHP_Project_Roadmap&amp;diff=22381</id>
		<title>OWASP PHP Project Roadmap</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_PHP_Project_Roadmap&amp;diff=22381"/>
				<updated>2007-10-12T17:27:51Z</updated>
		
		<summary type="html">&lt;p&gt;Kaf: /* Goals */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Goals==&lt;br /&gt;
The OWASP PHP Project's overall goal is to...&lt;br /&gt;
&lt;br /&gt;
 Produce materials that show PHP architects, developers, and&lt;br /&gt;
 deployers how to deal with most common application security&lt;br /&gt;
 problems throughout the lifecycle.&lt;br /&gt;
&lt;br /&gt;
In the near term, we are focused on the following tactical goals:&lt;br /&gt;
&lt;br /&gt;
# Inplementing Security using Best Practices (Non Framework Based Applications)&lt;br /&gt;
# Provide examples of how to prevent Cross Site Scripting attacks in popular web frameworks&lt;br /&gt;
# Provide examples of how to prevent SQL Injection in popular data access frameworks&lt;br /&gt;
# Provide examples of how to prevent Cross Site Scripting attacks in popular AJAX frameworks &lt;br /&gt;
# Provide examples of how to prevent LDAP injection in PHP&lt;br /&gt;
# Secure configuration guides&lt;br /&gt;
&lt;br /&gt;
==Current Tasks==&lt;br /&gt;
&lt;br /&gt;
* Call for volunteers - Join the [http://lists.owasp.org/mailman/listinfo/owasp-phpness mailing list], read the [[Tutorial]] and get started!&lt;br /&gt;
* Refine this roadmap in the [http://www.owasp.org/index.php/Talk:OWASP_PHP_Project_Roadmap discussion]. &lt;br /&gt;
&lt;br /&gt;
==Ideas==&lt;br /&gt;
&lt;br /&gt;
Please submit your ideas for the OWASP PHP Project here. (you can sign your ideas by adding four tilde characters like this &amp;lt;nowiki&amp;gt;~~~~&amp;lt;/nowiki&amp;gt;)&lt;br /&gt;
&lt;br /&gt;
[[User:Vanderaj|Vanderaj]] 06:57, 26 June 2006 (EDT)&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP PHP Project]]&lt;/div&gt;</summary>
		<author><name>Kaf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Kaf&amp;diff=22380</id>
		<title>User:Kaf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Kaf&amp;diff=22380"/>
				<updated>2007-10-12T17:10:25Z</updated>
		
		<summary type="html">&lt;p&gt;Kaf: New page: Javier Gloria&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Javier Gloria&lt;/div&gt;</summary>
		<author><name>Kaf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=PHP_File_Inclusion&amp;diff=22087</id>
		<title>PHP File Inclusion</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=PHP_File_Inclusion&amp;diff=22087"/>
				<updated>2007-10-03T17:12:23Z</updated>
		
		<summary type="html">&lt;p&gt;Kaf: /* Related Threats */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Vulnerability}}&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
PHP as many other languages allow the inclution of files in order to provide or extend the functionality of the current file.&lt;br /&gt;
&lt;br /&gt;
==Examples ==&lt;br /&gt;
&amp;lt;?PHP &lt;br /&gt;
include '/path/filename.php';&lt;br /&gt;
include_once 'path/filename.class.php';&lt;br /&gt;
require '../path/filename.inc';&lt;br /&gt;
require_once 'filename.inc.php';&lt;br /&gt;
?&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Related Threats==&lt;br /&gt;
Remote file inclusion using variables from the request POST or GET&lt;br /&gt;
&lt;br /&gt;
==Related Attacks==&lt;br /&gt;
&lt;br /&gt;
==Related Vulnerabilities==&lt;br /&gt;
&lt;br /&gt;
==Related Countermeasures==&lt;br /&gt;
&lt;br /&gt;
==Categories==&lt;br /&gt;
&lt;br /&gt;
{{Template:Stub}}&lt;br /&gt;
&lt;br /&gt;
[[Category:PHP]]&lt;/div&gt;</summary>
		<author><name>Kaf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=PHP_File_Inclusion&amp;diff=22086</id>
		<title>PHP File Inclusion</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=PHP_File_Inclusion&amp;diff=22086"/>
				<updated>2007-10-03T17:11:16Z</updated>
		
		<summary type="html">&lt;p&gt;Kaf: /* Examples */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Vulnerability}}&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
PHP as many other languages allow the inclution of files in order to provide or extend the functionality of the current file.&lt;br /&gt;
&lt;br /&gt;
==Examples ==&lt;br /&gt;
&amp;lt;?PHP &lt;br /&gt;
include '/path/filename.php';&lt;br /&gt;
include_once 'path/filename.class.php';&lt;br /&gt;
require '../path/filename.inc';&lt;br /&gt;
require_once 'filename.inc.php';&lt;br /&gt;
?&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Related Threats==&lt;br /&gt;
&lt;br /&gt;
==Related Attacks==&lt;br /&gt;
&lt;br /&gt;
==Related Vulnerabilities==&lt;br /&gt;
&lt;br /&gt;
==Related Countermeasures==&lt;br /&gt;
&lt;br /&gt;
==Categories==&lt;br /&gt;
&lt;br /&gt;
{{Template:Stub}}&lt;br /&gt;
&lt;br /&gt;
[[Category:PHP]]&lt;/div&gt;</summary>
		<author><name>Kaf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=PHP_File_Inclusion&amp;diff=22085</id>
		<title>PHP File Inclusion</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=PHP_File_Inclusion&amp;diff=22085"/>
				<updated>2007-10-03T17:09:26Z</updated>
		
		<summary type="html">&lt;p&gt;Kaf: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Vulnerability}}&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
PHP as many other languages allow the inclution of files in order to provide or extend the functionality of the current file.&lt;br /&gt;
&lt;br /&gt;
==Examples ==&lt;br /&gt;
&lt;br /&gt;
==Related Threats==&lt;br /&gt;
&lt;br /&gt;
==Related Attacks==&lt;br /&gt;
&lt;br /&gt;
==Related Vulnerabilities==&lt;br /&gt;
&lt;br /&gt;
==Related Countermeasures==&lt;br /&gt;
&lt;br /&gt;
==Categories==&lt;br /&gt;
&lt;br /&gt;
{{Template:Stub}}&lt;br /&gt;
&lt;br /&gt;
[[Category:PHP]]&lt;/div&gt;</summary>
		<author><name>Kaf</name></author>	</entry>

	</feed>