<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Interesting thing found at OSCON: Taint</title><link>http://blogs.msdn.com/garretts/archive/2008/07/23/interesting-thing-found-at-oscon-taint.aspx</link><description>I attended a session this morning called &amp;quot; PHP Taint Tool: It Ain't a Parser &amp;quot; by Luke Welling. Luke introduced a tool he's working on at OmniTI that is designed to assist in sniffing out where the potential for untrusted input is handled. From</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Interesting thing found at OSCON: Taint</title><link>http://blogs.msdn.com/garretts/archive/2008/07/23/interesting-thing-found-at-oscon-taint.aspx#8787299</link><pubDate>Tue, 29 Jul 2008 08:37:01 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8787299</guid><dc:creator>Tarique Sani</dc:creator><description>&lt;p&gt;Rasmus like to call his tool &amp;quot;scanmus&amp;quot; or atleast he did when I first saw it in 2005 Linux Banglore conference.&lt;/p&gt;
&lt;p&gt;For mere mortals like me there is &lt;a rel="nofollow" target="_new" href="https://chorizo-scanner.com/"&gt;https://chorizo-scanner.com/&lt;/a&gt; which is PHP specific scanner and is commercial or one could try the Ratproxy &lt;a rel="nofollow" target="_new" href="http://code.google.com/p/ratproxy/"&gt;http://code.google.com/p/ratproxy/&lt;/a&gt; from Google.&lt;/p&gt;
&lt;p&gt;Currently there is no alternative to the Taint tool but one could use something like Inspeckt &lt;a rel="nofollow" target="_new" href="http://code.google.com/p/inspekt/"&gt;http://code.google.com/p/inspekt/&lt;/a&gt; &lt;/p&gt;</description></item></channel></rss>