About the Author

Chris Shiflett

Chris Shiflett is an author and speaker who leads the web application security practice at OmniTI.


In Chicago for php|tek

After a very long and eventful day filled with multiple cancellations, delays, and overbooked hotels, I'm finally in Chicago (well, Schaumburg) and ready for php|tek. I'm fighting a cold (and currently losing; the travel problems haven't helped), so I might be incognito Wednesday morning while I try to recover. I should be around before my talk at the end of the day Wednesday, and of course I'll be around for the remainder of the conference after that. If you're going to be here, please stop by and introduce yourself.

I'm giving two talks, and the one I'm most excited about is The Truth about Sessions. This talk is similar to one I gave a few years ago in Toronto, but this time it's better. :-) The talk focuses on teaching you exactly how sessions work, beginning with the very basics (HTTP, statelessness, etc.). I spend a bit of time talking about session security at the end, but if I do my job, you'll understand sessions well enough by that point to devise solutions to basic security problems yourself. It's definitely a teach a man to fish talk.

My other talk is called PHP Security by Example, and it's more hands-on. The time slot of one hour isn't enough to let you work through each of the exercises independently, but I have tried to structure the talk to make it easy to follow along, so bring your laptop.

By the way, if you're wondering why Sean is so excited about Andy McKee, check out the highest rated videos on YouTube. (He currently holds 3 of the top 6 slots.) His mastery of the guitar reminds me of Kaki King, and I'm sure it will be really cool to watch him play Thursday night.

About This Post

In Chicago for php|tek was posted on Wed, 16 May 2007 at 06:32:44 GMT.

4 Comments

1. Keith Casey's GravatarKeith Casey said:

I grew up just south of Chicago and love it. I wish I could have made this one.

If you get the chance and like pizza, check out Giordano's - http://www.giordanos.com/locations.php ... simply amazing. It's an inch thick, dripping in cheese, and covered in sauce. ;)

Wed, 16 May 2007 at 13:32:22 GMT Link


2. Chris Shiflett's GravatarChris Shiflett said:

Thanks for the recommendation, Keith. I'm not a big fan of Chicago-style pizza myself, but I'm sure someone here is. :-)

Wed, 16 May 2007 at 15:07:14 GMT Link


3. Phillip Roberts's GravatarPhillip Roberts said:

A true New Yorker wants New York style pizza... :)

Thu, 17 May 2007 at 14:26:56 GMT Link


4. David D's GravatarDavid D said:

Hey Chris, enjoyed your talk... we're still waiting for the .tgz from this presentation.

Thu, 17 May 2007 at 18:03:27 GMT Link


Post A Comment

Personal Details and Comment

Style Guide

Line breaks are converted to paragraphs. Also use:

  • <a href="" title="">text</a>1
  • <em>text</em>
  • <blockquote><p>text</p></blockquote>
  • <code>2  <?php  if ($foo) {      $foo = TRUE;  }  ?></code>
  1. Note: <code> can be used inline (e.g. in paragraphs) or in a block as shown. Include whitespace and newlines in blocks.

Please enter Chris (my first name) below. This is a primitive spam prevention technique, and I apologize for the inconvenience.

Preview and Submit

Upcoming Talks

php|tek

21 - 23 May 2008

At Sheraton Gateway Suites Chicago O'Hare, Chicago, Illinois.

DC PHP Conference

02 - 04 Jun 2008

At Cafritz Conference Center, Washington, District of Columbia.

O'Reilly Open Source Convention

21 - 25 Jul 2008

At Oregon Convention Center, Portland, Oregon.

ZendCon

15 - 18 Sep 2008

In Santa Clara, California.

PHP Appalachia

11 - 14 Oct 2008

At Big Bear Lodge, Gatlinburg, Tennessee.

New Comments

Joseph Crawford wrote:

404 not found :( What's with this OpenID thing, you know how long it took me to figure out I h...

Posted in Zend Framework Tutorial
Laurent Cottereau wrote:

I am very interested in the possibilities of this service. However, I am wondering about what is ...

Posted in OpenID with myVidoop
Zac wrote:

Awesome code! Thanks!

Posted in Convert Smart Quotes with PHP
Muttley wrote:

Thanks for this, Shiffers. I've been working on a similar thing, using a similar method, so it's ...

Posted in Allowing HTML and Preventing XSS
hossein wrote:

Hi! May you give me an example how to use mcrypt_encrypt() in order to save passwrod in databa...

Posted in OpenID with myVidoop

Browse Comments