Researchers have built a tool that automatically finds and exploits SQL injection and cross-site scripting vulnerabilities in Web applications.
The so-called Ardilla tool uses a technique developed by the researchers — MIT’s Adam Kiezun, the University of Washington’s Michael Ernst, Stanford’s Philip Guo, and Syracuse University’s Karthick Jayaraman — that creates inputs that pinpoint bugs in Web applications and then generates SQL injection and XSS attacks. Ardilla is for PHP-based Web apps.
There is also a table of results from analysis done against several PHP web applications
Via: darkREADING
Oracle and Intel are now working together on enterprise Could Computing that will use encryption for improved privacy on data, the two companies said at this week’s OracleWorld conference.
Data encryption was mentioned as part of a larger agreement which also calls for collaboration around greater database performance for corporate clouds and mutual work on Web standards for cloud provisioning and management, as well as on the Open Virtual Format (OPF) for porting virtual machine images across platforms.
The collaboration will revolve around Intel Virtualization Technology (VT) and Oracle Grid Computing technologies such as Oracle’s database, Real Application Clusters (RAC), Automatic Storage Management, Application Grid, Enterprise Manager, and VM.
More can be read at C-NET
Linux.com has a detailed step by step installation procedure for installing Apache, MySQL and PHP on FreeBSD using the ports collection. Some extra steps are taken to secure the installation and you end up with a nice multifunctional FreeBSD+AMP setup with very little effort.
Ruan is a resolute technophile that is currently devoted to the professional practice of Information Technology Management. In his free time Ruan pursues various interests including the study of Information Security practices and the exploration of visual culture through contemporary photography and communication design.