Bug #78467 [Com]: Impossible to use PDO to connect to MySQL with ClearText Plugin
| From: | henry dot paradiz at gmail dot com | Date: | Mon, 07 Oct 2019 14:42:15 +0000 |
| Subject: | Bug #78467 [Com]: Impossible to use PDO to connect to MySQL with ClearText Plugin | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-223114@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78467&edit=1
ID: 78467
Comment by: henry dot paradiz at gmail dot com
Reported by: henry dot paradiz at gmail dot com
Summary: Impossible to use PDO to connect to MySQL with
ClearText Plugin
Status: Open
Type: Bug
Package: PDO MySQL
Operating System: Any
PHP Version: 7.1.31
Block user comment: N
Private report: N
New Comment:
Maybe cause there's literally millions of sites out there running 5.x that aren't being
hacked left and right? Not all things need fort knox built around them.
I'm routinely amazed at the lack of faith engineers in this subreddit have in the collective
security structure of systems like Linux. Exploits are rare and usually involve esoteric PHP
extensions and non-standard data manipulation techniques which most PHP code does not use.
I'm not trolling at all. I'm sure the code I wrote in 2014 would be fine on the open
internet running 5.6.
To be honest I've never been hacked in my career and I've worked on some pretty high
profile high traffic sites with some super janky code I've inherited. We're all connected
to the internet on routers running old versions of Linux and it's fine.
Previous Comments:
------------------------------------------------------------------------
[2019-10-07 14:41:27] henry dot paradiz at gmail dot com
I can tell you're less experienced cause you think packagist stats are accurate. Not everyone
uses composer. And it's based on the CLI version at run time which is skewed towards CI docker
images and workstations.
Priv escalation is something you will never pull off in your entire career so I don't know why
you bring it up. Maaaaaybe a well placed gd exploiting jpeg with a buffer overflow. Anyway it's
stupid to even think about.
My code needed very little change from 5.6 to 7 so good luck with that.
Here's my blog's source code. Have fun hacking it.
https://github.com/hparadiz/technexus
While you're at it bring me a beer. I'll wait.
------------------------------------------------------------------------
[2019-10-07 14:40:52] henry dot paradiz at gmail dot com
I'm not angry just have zero patience for arrogance, ignorance, and stupidity. The OP of this
thread hasn't been exploited or hacked. Most PHP out there is still running 5.x.
You are neither qualified nor smart enough to put together a single one of these hacks you claim we
are vulnurable to. You're spreading fear and FUD.
Linux is designed for security. The server is not running as root and neither is the PHP process on
the box.
This is like bitching about someone using Windows 95 to play Doom. Yea they could be hacked but
nothing of value would be lost and you're still just an asshole.
------------------------------------------------------------------------
[2019-10-07 14:40:19] henry dot paradiz at gmail dot com
I don't want them to maintain old versions. Just don't remove the old versions from
package managers.
If I want to install old software that's my right and my risk to take. That's not up to
you to decide. The vast majority of code written for 5.x could never be exploited anyway.
This is the height of nerd arrogance. Don't patronize me assholes. I'll figure out the
risk for myself. If I feel like running php 4.0 on Slackware 3.1 I'll do it and that's
none of your business.
------------------------------------------------------------------------
[2019-10-07 14:39:02] henry dot paradiz at gmail dot com
This is why dropping old versions from package managers is stupid.
------------------------------------------------------------------------
[2019-10-03 20:52:52] henry dot paradiz at gmail dot com
The following pull request has been associated:
Patch Name: protect master branches except for the pecl repos against force pushes
On GitHub: https://github.com/php/karma/pull/4
Patch: https://github.com/php/karma/pull/4.patch
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78467
--
Edit this bug report at https://bugs.php.net/bug.php?id=78467&edit=1