<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; PHP</title>
	<atom:link href="http://www.megapanzer.com/tag/php/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.megapanzer.com</link>
	<description></description>
	<lastBuildDate>Fri, 23 Dec 2011 13:02:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Interesting PHP injection</title>
		<link>http://www.megapanzer.com/2010/09/02/interesting-php-injection/</link>
		<comments>http://www.megapanzer.com/2010/09/02/interesting-php-injection/#comments</comments>
		<pubDate>Thu, 02 Sep 2010 16:45:06 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3904</guid>
		<description><![CDATA[Read on Sans PHP injection attacks have become increasingly popular lately. If you look at your web server logs I’m pretty sure that you will find dozens of requests for PHP injection, usually by bots that are simply trying some well known (and less known) vulnerabilities. One of our readers, Blake, managed to capture some [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" /><strong>Read on Sans</strong><br />
<br />
PHP injection attacks have become increasingly popular lately. If you look at your web server logs I’m pretty sure that you will find dozens of requests for PHP injection, usually by bots that are simply trying some well known (and less known) vulnerabilities.<br />
One of our readers, Blake, managed to capture some interesting attempts to <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=2563" title="Glossary: Exploit" target="_blank">exploit</a> various PHP injection vulnerabilities on his web site, thanks to installation of mod_security. Contrary to popular PHP injection attempts, where the attacker tries to <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=2563" title="Glossary: Exploit" target="_blank">exploit</a> a variable to get the PHP interpreter to retrieve a remote PHP script, Blake noticed that the attacker tried to <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=2563" title="Glossary: Exploit" target="_blank">exploit</a> a vulnerability in a PHP script through POST request. The attacker submitted a malicious PHP script (with other data) hoping that the PHP interpreter will execute it – this vulnerability also exist, although not that common. Here is what the attack looked like in log files &#8230;</p>
<p>Read more <a href="http://isc.sans.edu/diary.html?storyid=9478" target="_blank">here</a>.</p></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/09/02/interesting-php-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unanonymity 0.3 : PHP script to reveal user data</title>
		<link>http://www.megapanzer.com/2009/08/10/unanonymity-0-3-php-script-to-reveal-user-data/</link>
		<comments>http://www.megapanzer.com/2009/08/10/unanonymity-0-3-php-script-to-reveal-user-data/#comments</comments>
		<pubDate>Mon, 10 Aug 2009 22:25:25 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Tools & sources]]></category>
		<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[source]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=2576</guid>
		<description><![CDATA[Tool name : Unanonymity 0.3 &#160; Description : Unanonymity is a PHP script that collects all user data on the web server side and also on the web client side to show what kind of information the server owner can see from the user if they want. In this release the LAN host scanner feature [...]]]></description>
			<content:encoded><![CDATA[<table border="0" width="100%">
<tbody>
<tr valign="top">
<td width="30%"></td>
<td width="70%"></td>
</tr>
<tr valign="top">
<td><strong>Tool name</strong> :</td>
<td>Unanonymity 0.3</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Description</strong> :</td>
<td>Unanonymity is a PHP script that collects all user data on the web server side and also on the web client side to show what kind of information the server owner can see from the user if they want.<br />
In this release the LAN host scanner feature was implemented.
</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Tested on</strong> :</td>
<td>Firefox 3.0.7 on Windows XP</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr>
<td><strong>Feedback</strong> :</td>
<td>In case you encounter any problems with the tool, you have suggestions to improve it, or you tested it with a Windows version i&#8217;ve not yet tested please drop me an <a href="http://www.megapanzer.com/contact/">email</a>.</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Downloads</strong> :</td>
<td>Binary | <a href="http://www.megapanzer.com/wp-content/uploads/unanonymityphp_0_3.txt" target="_blank">Source</a></td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Online example</strong> :</td>
<td><a href="http://www.megapanzer.com/wp-content/uploads/unanonymity_0_3.php" target="_blank">Example</a></td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/08/10/unanonymity-0-3-php-script-to-reveal-user-data/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Unanonymity 0.1 : PHP script to reveal user data</title>
		<link>http://www.megapanzer.com/2009/06/30/unanonymity-php-script-to-reveal-user-data/</link>
		<comments>http://www.megapanzer.com/2009/06/30/unanonymity-php-script-to-reveal-user-data/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 16:48:43 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Tools & sources]]></category>
		<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Sources]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=2187</guid>
		<description><![CDATA[Tool name : Unanonymity 0.1 &#160; Description : Unanonymity is a PHP script that collects all user data on the web server side and also on the web client side to show what information the server owner can see from the user if they want. This is the first version of the script. In the [...]]]></description>
			<content:encoded><![CDATA[<table border="0" width="100%">
<tbody>
<tr valign="top">
<td width="30%"></td>
<td width="70%"></td>
</tr>
<tr valign="top">
<td><strong>Tool name</strong> :</td>
<td>Unanonymity 0.1</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Description</strong> :</td>
<td>Unanonymity is a PHP script that collects all user data on the web server side and also on the web client side to show what information the server owner can see from the user if they want.<br />
This is the first version of the script. In the next release I will analyze the Javascript portscanner to scan the users intranet and if feasible other suggestions if you leave a message.
</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Tested on</strong> :</td>
<td>Firefox 3.0.7 on Windows XP</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr>
<td><strong>Feedback</strong> :</td>
<td>In case you encounter any problems with the tool, you have suggestions to improve it, or you tested it with a Windows version i&#8217;ve not yet tested please drop me an <a href="http://www.megapanzer.com/contact/">email</a>.</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Downloads</strong> :</td>
<td>Binary | <a href="http://www.megapanzer.com/wp-content/uploads/unanonymityphp.txt" target="_blank">Source</a></td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Online example</strong> :</td>
<td><a href="http://www.megapanzer.com/wp-content/uploads/unanonymity.php" target="_blank">Example</a></td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/06/30/unanonymity-php-script-to-reveal-user-data/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

