Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Registered User
    Join Date
    Jan 2008
    Posts
    3

    Default PHP-Intrusion Detection System

    It would be a really good idea to add a module for PHPIDS.
    Right now I am using it on High risk Websites however Having to install it etc every time and set it all up is a pain, Would be great to have a module config it all to use on all accounts and E-Mail the root user to what is going on etc.

    PHPIDS » Web Application Security 2.0

  2. #2
    BANNED
    Join Date
    Jun 2005
    Location
    Wild Wild West
    Posts
    2,025

    Lightbulb

    It's not an Apache module, so it really doesn't work like that and users
    may have different applications to use, etc.

    You could load this for everything with a forced prepend in PHP.INI but
    then again there really may not much use for it.

    With SuPHP with SuHosin and proper PHP.INI configuration, there
    is little chance of an attack such as what IDS watches for from
    being even remotely successful and it's own job role can already
    be filled from other components such as Mod_Security and CFS.

  3. #3
    Member
    Join Date
    Oct 2006
    Location
    Cheshire, UK
    Posts
    196

    Default

    PHP security doesn't have to be such a risk if the application has been developed properly - it's up to the developer to secure their application. Application Firewalls are just an additional layer of protection, but not the answer.

  4. #4
    BANNED
    Join Date
    Jun 2005
    Location
    Wild Wild West
    Posts
    2,025

    Default

    PHP security doesn't have to be such a risk if the application has been developed properly - it's up to the developer to secure their application. Application Firewalls are just an additional layer of protection, but not the answer.
    I strongly disagree! You are assuming that the program programs perfectly without the slightest possible degree of error and can take into account every contingency and every possible interaction of every function.

    The PHP language is enormously complex and even with an expert level understanding of the language, you may not think of every possible misuse of functions or how certain data will behave in certain conditions.

    Ignoring all of the above, there is also the possibility of simple typographical error. Forget a single punctuation mark in the wrong place and you could turn an otherwise fairly safe application into a dangerous one.

    The purpose of IDS and SuHosin type security addons is not meant to replace the programmer but rather to help in those areas the programmer may have missed or for exploit possibilities which have not yet been discovered.

    It is a supplement to good programming and a life saver to bad programming!

    In a hosting service environment where you cannot guarantee whether a client's programs will be well designed and programmed with an interest in security or a careless slapped together code goo full of blatant security holes, you definitely need that extra layer of protection!

Similar Threads & Tags
Similar threads

  1. Intrusion Detection cpanel
    By liang3391 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-17-2009, 09:27 AM
  2. What is a good intrusion detection system I can use for my cpanel server?
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 12-14-2007, 08:46 PM
  3. AIDE - Advanced Intrusion Detection Environment
    By sh4ka in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 09-06-2005, 05:32 PM
  4. What kind of Intrusion Detection System is appropriate for a web server?
    By AbeFroman in forum cPanel and WHM Discussions
    Replies: 11
    Last Post: 02-25-2004, 02:19 PM
  5. Anyone know how to debug this intrusion.
    By DWHS.net in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 06-15-2003, 01:08 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube