data:image/s3,"s3://crabby-images/05d1d/05d1d3d7b065ba118c30ca7cf7c72dee815a92f5" alt="Picture of Nikos M. Picture of Nikos M."
Nikos M. - 2013-05-07 20:08:13
Trying to match possible vulnerabilities in a fast manner, using grep is a good approach.
This is more or less how anti-virus applications work, with scanning signatures.
The problme is that nowadays, no hacker with some knowledge, or without any, will use raw php, but rather obfuscated, either hand-crafted or a ready-made script.
The next step is to extend these grep searches for patterns like:
base64_decode(), eval(), etc..
or combinations