Bug->Req #78467 [Opn]: Impossible to use PDO to connect to MySQL with ClearText Plugin

From: Date: Tue, 06 Jul 2021 13:46:37 +0000
Subject: Bug->Req #78467 [Opn]: Impossible to use PDO to connect to MySQL with ClearText Plugin
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234815@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78467&edit=1 ID: 78467 Updated by: cmb@php.net Reported by: henry dot paradiz at gmail dot com Summary: Impossible to use PDO to connect to MySQL with ClearText Plugin Status: Open -Type: Bug +Type: Feature/Change Request Package: PDO MySQL Operating System: Any PHP Version: 7.1.31 Block user comment: Y Private report: N New Comment: This is a general mysqlnd issue, which selects the authentication plugin to use from what the server asks for, but does not allow to explicitly specify the authentication plugin, even though a cleartext_plugin is built-in, but apparently this can only be used for PAM authentication. Previous Comments: ------------------------------------------------------------------------ [2019-10-07 14:43:38] henry dot paradiz at gmail dot com Literally my point. Lol. Thanks for making it. ------------------------------------------------------------------------ [2019-10-07 14:43:04] henry dot paradiz at gmail dot com Lol inb4 shared hosts running multiple versions of PHP. ------------------------------------------------------------------------ [2019-10-07 14:42:39] henry dot paradiz at gmail dot com https://w3techs.com/technologies/details/pl-php/all/all You're the one cherry picking. If you were intellectually honest you'd look up stats from servers on the open internet which is a way bigger pool than composer installs. The stupid. It burns. ------------------------------------------------------------------------ [2019-10-07 14:42:15] henry dot paradiz at gmail dot com Maybe cause there's literally millions of sites out there running 5.x that aren't being hacked left and right? Not all things need fort knox built around them. I'm routinely amazed at the lack of faith engineers in this subreddit have in the collective security structure of systems like Linux. Exploits are rare and usually involve esoteric PHP extensions and non-standard data manipulation techniques which most PHP code does not use. I'm not trolling at all. I'm sure the code I wrote in 2014 would be fine on the open internet running 5.6. To be honest I've never been hacked in my career and I've worked on some pretty high profile high traffic sites with some super janky code I've inherited. We're all connected to the internet on routers running old versions of Linux and it's fine. ------------------------------------------------------------------------ [2019-10-07 14:41:27] henry dot paradiz at gmail dot com I can tell you're less experienced cause you think packagist stats are accurate. Not everyone uses composer. And it's based on the CLI version at run time which is skewed towards CI docker images and workstations. Priv escalation is something you will never pull off in your entire career so I don't know why you bring it up. Maaaaaybe a well placed gd exploiting jpeg with a buffer overflow. Anyway it's stupid to even think about. My code needed very little change from 5.6 to 7 so good luck with that. Here's my blog's source code. Have fun hacking it. https://github.com/hparadiz/technexus While you're at it bring me a beer. I'll wait. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78467 -- Edit this bug report at https://bugs.php.net/bug.php?id=78467&edit=1

« previous php.bugs (#234815) next »