Live-Hacking a Symfony application

aramido founder Andreas Sperber is a guest at SensioLabs in Cologne on December 21, 2016. At the meeting of the Symfony UserGroup, he demonstrates a hack of a Symfony application. Afterwards, he shows how to protect yourself from certain attacks and how developers can generate secure code. This demonstration is a short excerpt from aramido's Secure Coding training , which is intended for developers of web applications, for example using the PHP language and the Symfony framework.

IT Security and Symfony

Symfony is one of the most successful PHP frameworks. It is used as a framework and with its components both in custom developments and in systems such as Magento, Shopware, Wordpress and many others. The framework makes the work easier for developers and also forces them to generate good code. Nevertheless, serious errors can be made, which make it easy for hackers. Examples of errors in input validation, output escaping or rights management are shown as live hacks. Afterwards, it is shown for the example application how corresponding source code can be implemented securely.

About the speaker

Andreas Sperber
Andreas Sperber is co-founder and managing director of aramido GmbH. He has been working with Symfony since version 1.0 and has known the framework for many years. aramido advises companies on the topic of IT security and checks through penetration tests whether they would withstand a hacking attack. Andreas Sperber was previously CTO at the private accommodation intermediary gloveler and knows the web industry: there is still a lot to do regarding IT security.

IT-Security: Hacking a Symfony application

December 21, 2016, 6:30 PM to 9:00 PM
IT-Security: Hacking a Symfony application
SensioLabs, Neusser Straße 27–29, Cologne
Admission is free | An event of the Symfony UserGroup Cologne