data:image/s3,"s3://crabby-images/80424/8042440010bb0d997d2190ef11dcac4edec4b8f4" alt="Picture of Nikos M. Picture of Nikos M."
Nikos M. - 2013-05-07 20:08:13
Trying to match possible vulnerabilities in a fast manner, using grep is a good approach.
This is more or less how anti-virus applications work, with scanning signatures.
The problme is that nowadays, no hacker with some knowledge, or without any, will use raw php, but rather obfuscated, either hand-crafted or a ready-made script.
The next step is to extend these grep searches for patterns like:
base64_decode(), eval(), etc..
or combinations