Re: Quick Code Audit
| From: | Stanislav Malyshev | Date: | Tue, 05 Sep 2000 10:43:38 +0000 |
| Subject: | Re: Quick Code Audit | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32115@lists.php.net to get a copy of this message | ||
>> i think it might be a good idea at this time for everyone who actively
>> develops the PHP language (whether you hack on zend or own a small
>> module/extension) to work through any outstanding security related issues
>> as soon as possible. if you're not sure how to fix it, i'm sure other
>> developers will be all too willing to help you out.
Well, the idea that code should be audited is definitely good
idea. However, this couldn't be "quick" - this is slow and sometimes
painful process.
On the other side, if someone would take on himself to be "security
watchdog" of PHP and gather and maintain list of known PHP security issues
- that would be very good.
--
Stanislav Malyshev stas@zend.com http://www.zend.com/
+972-3-6139665 ext.106