Bug #78467 [Com]: Impossible to use PDO to connect to MySQL with ClearText Plugin

From: Date: Mon, 07 Oct 2019 14:43:04 +0000
Subject: Bug #78467 [Com]: Impossible to use PDO to connect to MySQL with ClearText Plugin
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223116@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78467&edit=1 ID: 78467 Comment by: henry dot paradiz at gmail dot com Reported by: henry dot paradiz at gmail dot com Summary: Impossible to use PDO to connect to MySQL with ClearText Plugin Status: Open Type: Bug Package: PDO MySQL Operating System: Any PHP Version: 7.1.31 Block user comment: N Private report: N New Comment: Lol inb4 shared hosts running multiple versions of PHP. Previous Comments: ------------------------------------------------------------------------ [2019-10-07 14:42:39] henry dot paradiz at gmail dot com https://w3techs.com/technologies/details/pl-php/all/all You're the one cherry picking. If you were intellectually honest you'd look up stats from servers on the open internet which is a way bigger pool than composer installs. The stupid. It burns. ------------------------------------------------------------------------ [2019-10-07 14:42:15] henry dot paradiz at gmail dot com Maybe cause there's literally millions of sites out there running 5.x that aren't being hacked left and right? Not all things need fort knox built around them. I'm routinely amazed at the lack of faith engineers in this subreddit have in the collective security structure of systems like Linux. Exploits are rare and usually involve esoteric PHP extensions and non-standard data manipulation techniques which most PHP code does not use. I'm not trolling at all. I'm sure the code I wrote in 2014 would be fine on the open internet running 5.6. To be honest I've never been hacked in my career and I've worked on some pretty high profile high traffic sites with some super janky code I've inherited. We're all connected to the internet on routers running old versions of Linux and it's fine. ------------------------------------------------------------------------ [2019-10-07 14:41:27] henry dot paradiz at gmail dot com I can tell you're less experienced cause you think packagist stats are accurate. Not everyone uses composer. And it's based on the CLI version at run time which is skewed towards CI docker images and workstations. Priv escalation is something you will never pull off in your entire career so I don't know why you bring it up. Maaaaaybe a well placed gd exploiting jpeg with a buffer overflow. Anyway it's stupid to even think about. My code needed very little change from 5.6 to 7 so good luck with that. Here's my blog's source code. Have fun hacking it. https://github.com/hparadiz/technexus While you're at it bring me a beer. I'll wait. ------------------------------------------------------------------------ [2019-10-07 14:40:52] henry dot paradiz at gmail dot com I'm not angry just have zero patience for arrogance, ignorance, and stupidity. The OP of this thread hasn't been exploited or hacked. Most PHP out there is still running 5.x. You are neither qualified nor smart enough to put together a single one of these hacks you claim we are vulnurable to. You're spreading fear and FUD. Linux is designed for security. The server is not running as root and neither is the PHP process on the box. This is like bitching about someone using Windows 95 to play Doom. Yea they could be hacked but nothing of value would be lost and you're still just an asshole. ------------------------------------------------------------------------ [2019-10-07 14:40:19] henry dot paradiz at gmail dot com I don't want them to maintain old versions. Just don't remove the old versions from package managers. If I want to install old software that's my right and my risk to take. That's not up to you to decide. The vast majority of code written for 5.x could never be exploited anyway. This is the height of nerd arrogance. Don't patronize me assholes. I'll figure out the risk for myself. If I feel like running php 4.0 on Slackware 3.1 I'll do it and that's none of your business. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78467 -- Edit this bug report at https://bugs.php.net/bug.php?id=78467&edit=1

« previous php.bugs (#223116) next »