2.3.39. Security¶

This ruleset focuses on code security.

Total : 47 analysis

  • Eval() Usage

  • Phpinfo

  • var_dump()… Usage

  • Hardcoded Passwords

  • Direct Injection

  • Avoid sleep()/usleep()

  • parse_str() Warning

  • Avoid Those Hash Functions

  • No Hardcoded Port

  • Should Use Prepared Statement

  • No Hardcoded Ip

  • Compare Hash

  • preg_replace With Option e

  • eval() Without Try

  • Register Globals

  • Safe Curl Options

  • Use random_int()

  • No Hardcoded Hash

  • Random Without Try

  • Indirect Injection

  • Unserialize Second Arg

  • Don’t Echo Error

  • Should Use session_regenerateid()

  • Encoded Simple Letters

  • Set Cookie Safe Arguments

  • No Return Or Throw In Finally

  • Mkdir Default

  • Switch Fallthrough

  • Upload Filename Injection

  • Always Anchor Regex

  • Session Lazy Write

  • Sqlite3 Requires Single Quotes

  • No Net For Xml Load

  • Dynamic Library Loading

  • Configure Extract

  • move_uploaded_file Instead Of copy

  • filter_input() As A Source

  • Safe HTTP Headers

  • Insecure Integer Validation

  • Minus One On Error

  • No ENT_IGNORE

  • No Weak SSL Crypto

  • Keep Files Access Restricted

  • Check Crypto Key Length

  • Incompatible Types With Incoming Values

  • Filter Not Raw

  • Unvalidated Data Cached In Session

2.3.39.1. Specs¶

Short name

Security

Available in

Entreprise Edition, Exakat Cloud

Reports

Ambassador, Owasp

Exakat

Navigation

  • Introduction
  • Release Note

GETTING STARTED

  • Standard installation
  • Docker installation
  • Tutorials

USER GUIDE

  • Overview
  • PHP Version
  • Library & Framework Support
  • Configuration
  • Scoping analysis
  • Rule
  • Report
  • Cobbler

REFERENCE GUIDE

  • 1. Rules
  • 2. Rulesets
  • 3. Reports
  • 4. Cobblers
  • 5. Real Code Cases

ADMINISTRATOR GUIDE

  • Installation
  • Upgrading
  • Configuration
  • Commands

OTHERS

  • Frequently Asked Questions
  • Glossary
  • Annex

Related Topics

  • Documentation overview
    • 2. Rulesets
      • Previous: 2.3.38. Rector
      • Next: 2.3.40. Semantics
©2015-2025, Damien Seguy - Exakat. | Powered by Sphinx 9.0.4 & Alabaster 1.0.0 | Page source