Quick Code Audit
| From: | lists at itsg dot net dot au | Date: | Mon, 04 Sep 2000 23:33:43 +0000 |
| Subject: | Quick Code Audit | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-31987@lists.php.net to get a copy of this message | ||
dear dev list,
this message is not meant as an insult to the quality of code that has
been written so far for the project, or to the people writing it - so
please don't take it as one.
there have been 2 security issues that some might consider as
"major" appear within the space of the last week (safemode and forms).
it is obvious that third parties are at the moment auditing the codebase
for their own agendas (ie. sex-symbol status on bugtraq) and that this
will continue and could possibly damage the reputation of the php project
(even if it is in a small way).
i think it might be a good idea at this time for everyone who actively
develops the PHP language (whether you hack on zend or own a small
module/extension) to work through any outstanding security related issues
as soon as possible. if you're not sure how to fix it, i'm sure other
developers will be all too willing to help you out.
if anyone thinks i am outta line here, speak now etc, etc 8^)
thanks for listening,
- avi