Wednesday, December 19, 2012

Re: Penetration tests

Here I was running Cake 4 thinking "How did I miss 3?!"


On 19 December 2012 20:33, Jeremy Burns | Class Outfit <jeremyburns@classoutfit.com> wrote:
I did - and have corrected the post.


Jeremy Burns
Class Outfit

http://www.classoutfit.com

On 19 Dec 2012, at 12:31:47, euromark <dereuromark@gmail.com> wrote:

since 3.0 is not even close to being used productively (3.0.0-dev) he most likely means "2.3. beta" ;)


Am Mittwoch, 19. Dezember 2012 12:52:13 UTC+1 schrieb Sipatshi:

cakephp 3.0 Beta? where can i find it?



Von: Jeremy Burns <jerem...@classoutfit.com>
An: cake...@googlegroups.com
Gesendet: 12:49 Mittwoch, 19.Dezember 2012
Betreff: Penetration tests

Not so much a question as a pleasant observation.

I'm just finishing off a project built on CakePHP 3.0 beta using the ACL and Security components amongst others. As the site called for super tight security (it's a payment gateway of sorts) I had it penetration tested. The site accepts posts via http and even instructions via SMS messages - so there's plenty of potential for vulnerabilities. After ~49,000 tests it reported only 16 red issues, 11 of which related to either Apache or PHPMyAdmin and the remaining five don't present an actual risk to the site or server; they are potential cross site scripting risks that could be used to expose cookies on the user's machine.

I'd like to pat myself on the back and say these results were down to my brilliant coding, but in fairness all I did was use the tools at my disposal. So thanks and well done to the core developers for delivering an outstanding toolset.
--
Like Us on FaceBook https://www.facebook.com/CakePHP
Find us on Twitter http://twitter.com/CakePHP
 
---
You received this message because you are subscribed to the Google Groups "CakePHP" group.
To post to this group, send email to cake...@googlegroups.com.
To unsubscribe from this group, send email to cake-php+u...@googlegroups.com.
Visit this group at http://groups.google.com/group/cake-php?hl=en.
 
 



--
Like Us on FaceBook https://www.facebook.com/CakePHP
Find us on Twitter http://twitter.com/CakePHP
 
---
You received this message because you are subscribed to the Google Groups "CakePHP" group.
To post to this group, send email to cake-php@googlegroups.com.
To unsubscribe from this group, send email to cake-php+unsubscribe@googlegroups.com.
Visit this group at http://groups.google.com/group/cake-php?hl=en.
 
 

--
Like Us on FaceBook https://www.facebook.com/CakePHP
Find us on Twitter http://twitter.com/CakePHP
 
---
You received this message because you are subscribed to the Google Groups "CakePHP" group.
To post to this group, send email to cake-php@googlegroups.com.
To unsubscribe from this group, send email to cake-php+unsubscribe@googlegroups.com.
Visit this group at http://groups.google.com/group/cake-php?hl=en.
 
 

--
Like Us on FaceBook https://www.facebook.com/CakePHP
Find us on Twitter http://twitter.com/CakePHP
 
---
You received this message because you are subscribed to the Google Groups "CakePHP" group.
To post to this group, send email to cake-php@googlegroups.com.
To unsubscribe from this group, send email to cake-php+unsubscribe@googlegroups.com.
Visit this group at http://groups.google.com/group/cake-php?hl=en.
 
 

No comments: