Reply to auditing php programs?

Your name:

Reply:


Posted by yawnmoth on 12/06/06 22:19

I'm trying to perform an audit on a PHP script and am curious what kind
of software there already exists to do such things.

I think the ideal solution would be something that, for each variable,
provided a list of the functions that variable was passed through. eg.

$a = someFunction($_GET['var']);
echo $a;

function someFunction($b) {
return htmlspecialchars($b);
}

Here, $_GET['var'] passes through someFunction and htmlspecialchars
before getting passed to echo (which I suppose isn't technically a
function, but rather, a language construct).

if statements could kinda confound this, but it seems like presenting
the data in an appropriate fashion could mitigate that.

Anyway, any ideas?

[Back to original message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация