OWASP Top 10 for the Lazy PHP Developer
Talk • PHP • Security • OWASP
The talk that should have been at https://www.gunnard.org/talks/owasp-top-10-lazy-php.pdf — now also as a readable page.
Slides: Download PDF
Abstract
Most PHP security talks shame you for not hand-rolling perfect crypto. This one assumes you’re lazy — you want the least work that still keeps you out of the breach headlines.
We walk the OWASP Top 10 through real, boring PHP code: the app you actually ship (mysqli, sessions, file uploads, old Symfony/Laravel, or no framework at all). For each item: what the attack looks like, the one-line fix, and the habit that prevents the next one.
No FUD, no compliance theater. Just: here’s the bug, here’s the diff, here’s how to not do it again.
What you’ll take away
- Why injection is still #1 in PHP (and the 2 prepared-statement patterns that kill it)
- Auth/session bugs that survive
password_hash()— and what to check in 5 minutes - XSS without React — escaping where it actually matters in legacy templates
- A 30-minute checklist you can run on any PHP codebase next Monday
Resources
- Slides (PDF): /talks/owasp-top-10-lazy-php.pdf — placeholder deck; full version forthcoming. If you need the original conference deck, email me via /contact.
- More talks: /speaking/talks
Reported 404 fixed 2026-09-17 — thanks to Barbara Fletcher for the heads-up.