Login Register






What makes PHP so secure? filter_list
Author
Message
RE: What makes PHP so secure? #11
(01-21-2016, 09:16 PM)Cosvo Wrote: Hello sinisterly.
Sorry for not being active in the past, but I ended up doing something so blackhat that I never thought I was going to do, I was almost caught in the act, but anyways.

I want to know why PHP is one of the more secure language to code in.
For example PHP-rat, there you doesn't have to use any VPN because of it basically just is coded in PHP.
So, what does PHP so secure?

Because no one else seems to be willing to give you a proper answer, allow me.

PHP is secure in the sense that it doesn't (in theory) allow you to do unsafe memory operations that can make your application vulnerable or crash, but this isn't unique to PHP. PHP isn't any more secure than other popular languages like Python, Javascript, Java or C.

PHP is not secure in the sense that it's unhackable. That's a ridiculous claim which is easily proven false. Using PHP doesn't give your application any safety from hackers, researchers, crackers or pirates what-so-ever. As a matter of fact, if you choose PHP, odds are that you'll write an easily hackable application, because PHP coders tend to be Bad Programmers™. When coding in PHP, you also need to leave your source code open for anyone to see, which makes it easier to analyse and find exploits. You can obfuscate, but decent PHP obfuscators are far and few between (No, eval(gzuncompress(base64_decode())) is NOT decent obfuscation!)

As for PHP-rats not needing VPNs, that's just plain wrong. A VPN isn't needed for any RATs, PHP or not. What you might need is a proxy, but even that is rare. What PHP offers you is the ability to create HTTP requests with ease, and it gives you access to sockets with fsockopen, but you can replicate this in any language if you're skilled enough. I'd also like to recommend that you do not create RATs in PHP, simply because PHP doesn't have access to low-level system calls. The best you have in PHP is exec(), unless you write your own modules.

Hope this cleared things up a little bit.

TL;DR:
PHP is "secure" because it doesn't allow you to fuck around with memory.
PHP code is often easily hackable because PHP coders tend to suck.
PHP applications are not secure just because they're written in PHP.

[+] 2 users Like Rou's post

RE: What makes PHP so secure? #12
(01-22-2016, 10:59 AM)Rou Wrote: TL;DR:
PHP is "secure" because it doesn't allow you to fuck around with memory.
PHP code is often easily hackable because PHP coders tend to suck.
PHP applications are not secure just because they're written in PHP.

This is exactly correct. The memory fuckage is a big reason why server apps crash, but other than that, the security of the system is up to the programmer, just like everything else.

I forget where, but I remember reading that PHP has piss-all for built-in security, so it's really all up to the dev to not use shitty code.
It's often the outcasts, the iconoclasts ... those who have the least to lose because they
don't have much in the first place, who feel the new currents and ride them the farthest.


RE: What makes PHP so secure? #13
(01-22-2016, 10:59 AM)Rou Wrote: PHP is "secure" because it doesn't allow you to fuck around with memory.

(01-22-2016, 01:57 PM)Chitoge Wrote: This is exactly correct. The memory fuckage is a big reason why server apps crash, but other than that, the security of the system is up to the programmer, just like everything else.

I've seen shitty PHP code take down a server with 16 cores and 32GB ram if i recall correctly. Either way it was by far one of the beastiest machines i've ever touched. but it was a logic error in a loop that would run to its maximum execution time every time the script was hit. which i believe was configured to 2 minutes for some reason. so this never ending loop would run for 2 minutes putting shit in memory every time someone accessed it. and some spam bots started targetting the page because there was a web form on it. even though they couldn't actually submit anything, the fact that the page loaded was enough.

So ya - you don't need direct write access to the stack to cause issues with memory in PHP


RE: What makes PHP so secure? #14
(01-22-2016, 02:18 PM)The Real Slim Shady Wrote: I've seen shitty PHP code take down a server with 16 cores and 32GB ram if i recall correctly. Either way it was by far one of the beastiest machines i've ever touched. but it was a logic error in a loop that would run to its maximum execution time every time the script was hit. which i believe was configured to 2 minutes for some reason. so this never ending loop would run for 2 minutes putting shit in memory every time someone accessed it. and some spam bots started targetting the page because there was a web form on it. even though they couldn't actually submit anything, the fact that the page loaded was enough.

So ya - you don't need direct write access to the stack to cause issues with memory in PHP

Memory depletion and infinite loops are different issues from memory corruption and access violations, though.


RE: What makes PHP so secure? #15
(01-22-2016, 10:59 AM)Rou Wrote: Because no one else seems to be willing to give you a proper answer, allow me.

PHP is secure in the sense that it doesn't (in theory) allow you to do unsafe memory operations that can make your application vulnerable or crash, but this isn't unique to PHP. PHP isn't any more secure than other popular languages like Python, Javascript, Java or C.

PHP is not secure in the sense that it's unhackable. That's a ridiculous claim which is easily proven false. Using PHP doesn't give your application any safety from hackers, researchers, crackers or pirates what-so-ever. As a matter of fact, if you choose PHP, odds are that you'll write an easily hackable application, because PHP coders tend to be Bad Programmers™. When coding in PHP, you also need to leave your source code open for anyone to see, which makes it easier to analyse and find exploits. You can obfuscate, but decent PHP obfuscators are far and few between (No, eval(gzuncompress(base64_decode())) is NOT decent obfuscation!)

As for PHP-rats not needing VPNs, that's just plain wrong. A VPN isn't needed for any RATs, PHP or not. What you might need is a proxy, but even that is rare. What PHP offers you is the ability to create HTTP requests with ease, and it gives you access to sockets with fsockopen, but you can replicate this in any language if you're skilled enough. I'd also like to recommend that you do not create RATs in PHP, simply because PHP doesn't have access to low-level system calls. The best you have in PHP is exec(), unless you write your own modules.

Hope this cleared things up a little bit.

TL;DR:
PHP is "secure" because it doesn't allow you to fuck around with memory.
PHP code is often easily hackable because PHP coders tend to suck.
PHP applications are not secure just because they're written in PHP.

As i'm not much of a programmer, I was actually pretty interested in the answer. Sue me
Thanks for a valid response!


RE: What makes PHP so secure? #16
I like how no one answered his real question because he's too dumb to know how to ask it.
Here, kid: the reason a "PHP RAT" won't expose your IP is because the client is connecting back to a Web server, not a tool running on your PC.
It's not even really a "PHP RAT" by the way, it's just a set of scripts written to respond to HTTP requests from the infected machine.


RE: What makes PHP so secure? #17
This thread has gone far enough, and is not longer productive. Locked.