RE: What makes PHP so secure? 01-22-2016, 10:59 AM
#11
(01-21-2016, 09:16 PM)Cosvo Wrote: Hello sinisterly.
Sorry for not being active in the past, but I ended up doing something so blackhat that I never thought I was going to do, I was almost caught in the act, but anyways.
I want to know why PHP is one of the more secure language to code in.
For example PHP-rat, there you doesn't have to use any VPN because of it basically just is coded in PHP.
So, what does PHP so secure?
Because no one else seems to be willing to give you a proper answer, allow me.
PHP is secure in the sense that it doesn't (in theory) allow you to do unsafe memory operations that can make your application vulnerable or crash, but this isn't unique to PHP. PHP isn't any more secure than other popular languages like Python, Javascript, Java or C.
PHP is not secure in the sense that it's unhackable. That's a ridiculous claim which is easily proven false. Using PHP doesn't give your application any safety from hackers, researchers, crackers or pirates what-so-ever. As a matter of fact, if you choose PHP, odds are that you'll write an easily hackable application, because PHP coders tend to be Bad Programmers™. When coding in PHP, you also need to leave your source code open for anyone to see, which makes it easier to analyse and find exploits. You can obfuscate, but decent PHP obfuscators are far and few between (No, eval(gzuncompress(base64_decode())) is NOT decent obfuscation!)
As for PHP-rats not needing VPNs, that's just plain wrong. A VPN isn't needed for any RATs, PHP or not. What you might need is a proxy, but even that is rare. What PHP offers you is the ability to create HTTP requests with ease, and it gives you access to sockets with fsockopen, but you can replicate this in any language if you're skilled enough. I'd also like to recommend that you do not create RATs in PHP, simply because PHP doesn't have access to low-level system calls. The best you have in PHP is exec(), unless you write your own modules.
Hope this cleared things up a little bit.
TL;DR:
PHP is "secure" because it doesn't allow you to fuck around with memory.
PHP code is often easily hackable because PHP coders tend to suck.
PHP applications are not secure just because they're written in PHP.


![[Image: LocMEDM.png]](http://i.imgur.com/LocMEDM.png)
![[+]](https://sinister.li/images/modern/collapse_collapsed.png)


















![[Image: s7qusG8.png]](http://i.imgur.com/s7qusG8.png)








![[Image: qcYJ3l.png]](https://i.skull.moe/u/qcYJ3l.png)