Jeff Moser hat auf InfoQ einen interessanten Artikel veröffentlicht, der sich im Detail mit dem Ablauf einer HTTPS-Verbindung beschäftigt. In »The First Few Milliseconds of an HTTPS Connection« zerlegt er als Beispiel einen Aufruf von Amazon.com mit Bordmitteln (Firefox) und Wireshark.
PHP-Intrusion Detection System
PHPIDS (PHP-Intrusion Detection System) is a simple to use, well structured, fast and state-of-the-art security layer for your PHP based web application. The IDS neither strips, sanitizes nor filters any malicious input, it simply recognizes when an attacker tries to break your site and reacts in exactly the way you want it to. Based on a set of approved and heavily tested filter rules any attack is given a numerical impact rating which makes it easy to decide what kind of action should follow the hacking attempt. This could range from simple logging to sending out an emergency mail to the development team, displaying a warning message for the attacker or even ending the user’s session.