About the Author

Chris Shiflett

Hi, I’m Chris, a web craftsman making things like Mapalong & Brooklyn Beta with my friends at Analog.


ZendCon Day One

I'm attending the Zend PHP Conference and Expo (which I've decided to call ZendCon for convenience) this week. The conference is taking place at the Hyatt Regency in San Francisco (Burlingame if you're picky). The venue is very nice, and the business focus is proving to be more interesting than I expected.

Yesterday was the first day of the conference, but it was just tutorials, so it lacked the attendance, keynotes, and other stuff that accompanies the "real" conference days.

I gave a tutorial called Securing PHP Applications that I think went really well. The night before, I decided to cut out some material to make room for a case study of the Myspace worm. I think most people appreciated seeing a real-world scenario that solidified many of the topics I was discussing in the talk. I also think there is quite a bit of confusion and misunderstanding about the mechanics of the worm (specifically about the role XSS played). I plan to collect some of my notes and blog more details about that.

Most people seem particularly interested in the fact that AJAX was used to subvert the CSRF protection that Myspace employed. Someone reminded me that I described this scenario in a comment I made a month or two ago. It was also a scenario that I researched in a recent consulting engagement.

I plan to cover the conference pretty well in my blog, so stay tuned. :-)

About this post

ZendCon Day One was posted on Wed, 19 Oct 2005 at 19:24:23 GMT. Follow me on Twitter.

4 comments

1.Leonid Lukin said:

Hi, Chris! You can get a copy of your conference photo at http://www.phpworld.ru/images/photos/LnS.JPG.

Thanx a lot for your great tutorial!

Wed, 19 Oct 2005 at 21:58:48 GMT Link


2.Leonid Lukin said:

There is a wrong point at the end of the link -

http://www.phpworld.ru/images/photos/LnS.JPG

Wed, 19 Oct 2005 at 22:00:37 GMT Link


3.Chris Shiflett said:

Hi, Leonid. Thanks for the kind words and the photo. :-)

Thu, 20 Oct 2005 at 07:30:40 GMT Link


4.Dave said:

The security tutorial was excellent. Our whole team enjoyed it and we will be getting a copy of Chris' book to keep handy in the office. Thanks Chris.

Mon, 24 Oct 2005 at 16:33:11 GMT Link


Hello! What’s your name?

Want to comment? Please connect with Twitter to join the discussion.


Work and Books

Analog Essential PHP Security HTTP Developer's Handbook