Re: Quick Code Audit
| From: | Stanislav Malyshev | Date: | Wed, 06 Sep 2000 10:11:44 +0000 |
| Subject: | Re: Quick Code Audit | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32336@lists.php.net to get a copy of this message | ||
LTW>> Perhaps a more formal introduction and reference on programming PHP 4
LTW>> internals would be good: give folks who are writing extensions or
Security-wise, PHP internals (like Zend engine) is pretty safe, you can't
break anything unless you've done something stupid on previous layers,
like mixing zval's, modifying convert_..._ex result or something like
that. Most real "security" is in layers like safe_mode layer and fopen
wrappers and probably network code, which are pretty indifferent to Zend
internals.
--
Stanislav Malyshev stas@zend.com http://www.zend.com/
+972-3-6139665 ext.106