3 ms·
I’ve been developing in PHP and exploiting apps written in PHP for over ten years. A lot of the insecure by default functionality and footgun functions have be
by mikeodds 5y ago
I’ve been developing in PHP and exploiting apps written in PHP for over ten years.
A lot of the insecure by default functionality and footgun functions have been deprecated or removed in the latest versions.
Most of the modern frameworks e.g Laravel et al also have abstractions that protect you around a lot of the functionality where long hanging vulnerabilities used to lie. It’s rarer to find things like XSS, SQL inj, file inclusion vulns.
Type comparison will still do crazy things if you aren’t strict, but they have introduced typed properties in php 7.4.
A double edged sword is that a lot of modern development relies on package managers like composer, which means you can be exposed to security issues through the sheer number of dependencies pulled in to some of these frameworks.