data:image/s3,"s3://crabby-images/8c79e/8c79e884de3daf0c6e0136bb667e07e83376f667" alt="Picture of Nikos M. Picture of Nikos M."
Nikos M. - 2013-05-07 20:08:13
Trying to match possible vulnerabilities in a fast manner, using grep is a good approach.
This is more or less how anti-virus applications work, with scanning signatures.
The problme is that nowadays, no hacker with some knowledge, or without any, will use raw php, but rather obfuscated, either hand-crafted or a ready-made script.
The next step is to extend these grep searches for patterns like:
base64_decode(), eval(), etc..
or combinations