This course will teach students advanced methods and techniques for PHP applications audits at source code and at bytecode level. The students will get to know the most common PHP security problems and how to find them at source code and bytecode level. Throughout the course several free and open source software tools will be introduced and used in order to visualize application structure, find security problems with static and dynamic analysis on source code and bytecode level and also to break PHP bytecode encryption.
Ability to read, understand and develop PHP code.
Required software will be delivered in form of a VMWARE Ubuntu Linux installation.
Laptop Computer
Source Code Auditing
--------------------
Introduction to PHP Source Code Audits
Bytecode Level Auditing
-----------------------
Introduction to the Zend Engine
Instruction Set of the Zend Engine/PHP Bytecode
Powered by SyScan © 2010 SyScan'10