WebApp Sec mailing list archives

Re: MYSQL and PHP


From: "Robin Wood" <dninja () gmail com>
Date: Tue, 16 May 2006 17:18:04 +0100

On 5/16/06, Gerald Quakenbush <geraldq () mastermindsecuritygroup com> wrote:
John -

Of course, one should also get the code updated and have it read and encrypted
file and decrypt the credentials.


Gerald Quakenbush
Author of 'Web Hacker Boot Camp'
http://www.quakenbush.com


Doesn't this give you a chicken and egg situation of where do you
store the key for the encrypted file?

-------------------------------------------------------------------------
Sponsored by: Watchfire

Watchfire named worldwide market share leader in web application security
assessment by leading market research firm. Watchfire's AppScan is the
industry's first and leading web application security testing suite, and
the only solution to provide comprehensive remediation tasks at every
level of the application. See for yourself.
Download a Free Trial of AppScan 6.0 today!

https://www.watchfire.com/securearea/appscansix.aspx?id=701300000007t9c
--------------------------------------------------------------------------


Current thread: