RIPS Icon

RIPS

beta

Automated Security Analysis for PHP Applications

4.3 Stars (11)
494 Downloads (This Week)
Last Update:
Download rips-0.55.zip
Browse All Files

Screenshots

Description

RIPS is a static source code analyser for the detection of vulnerabilities in PHP applications. It was released 2010 during the Month of PHP Security (www.php-security.org).

NOTE: RIPS 0.5 development is abandoned. A complete rewrite with OOP support and higher precision is available at https://www.ripstech.com

RIPS Web Site

Features

  • detect XSS, SQLi, File disclosure, LFI/RFI, RCE vulnerabilities and more
  • 5 verbosity levels for debugging your scan results
  • mark vulnerable lines in source code viewer
  • highlight variables in the code viewer
  • user-defined function code by mouse-over on detected call
  • active jumping between function declaration and calls
  • list of all user-defined functions (defines and calls), program entry points (user input) and scanned files (with includes) connected to the source code viewer
  • graph visualization for files and includes as well as functions and calls
  • create CURL exploits for detected vulnerabilties with few clicks
  • visualization, description, example, PoC, patch and securing function list for every vulnerability
  • 7 different syntax highlighting colour schemata
  • display scan result in form of a top-down flow or bottom-up trace
  • only minimal requirement is a local webserver with PHP and a browser (tested with Firefox)
  • regex search function

KEEP ME UPDATED

User Ratings

★★★★★
★★★★
★★★
★★
9
0
0
0
2
ease 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 5 / 5
features 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 3 / 5
design 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 5 / 5
support 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 0 / 5
Write a Review

User Reviews

  • 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5

    Object-oriented code is not supported.

    Posted 11/28/2013
  • 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5

    This tool is quite useless. Developers who would benefit from this tool, would never write non-object-oriented code in a system large enough to require such an audit. And developers who only write procedural code would not know what to do with this information.

    Posted 03/21/2012
Read more reviews

Additional Project Details

User Interface

Web-based

Programming Language

PHP

Registered

2010-05-23

Thanks for helping keep SourceForge clean.

Screenshot instructions:
Windows
Mac
Red Hat Linux   Ubuntu

Click URL instructions:
Right-click on ad, choose "Copy Link", then paste here →
(This may not be possible with some types of ads)

More information about our ad policies
X

Briefly describe the problem (required):

Upload screenshot of ad (required):
Select a file, or drag & drop file here.

Please provide the ad click URL, if possible:

Get latest updates about Open Source Projects, Conferences and News.

Sign up for the SourceForge newsletter:

No, thanks
Screenshots can attract more users to your project.
Features can attract more users to your project.