RE: [PHP-DEV] CVS Account Request

From: Date: Wed, 15 Nov 2000 21:26:50 +0000
Subject: RE: [PHP-DEV] CVS Account Request
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-38194@lists.php.net to get a copy of this message
At 23:17 15/11/2000, Mike Robinson wrote:
Rasmus wrote: We have yet to have a problem and it feels to me like you are trying to fix something that isn't broken. IMHO, bingo.
I was actually meaning to try and test this system, by applying from a fake Email, obtaining access, and injecting a security hole into the source tree, just to show how easy it is. I finally decided against it, mainly due to lack of time. Do you guys remember the people who hacked apache.org? They did it just to show how easy it is, and if they weren't 'white hats', they could have easily injected bogus code into the most popular Web server in the world. PHP is the most popular opensource Web language in the world, and we shouldn't make it easier for hackers to get in. In my opinion, waiting for such a thing to happen instead of fixing it beforehand is, well, not-smart. CVS ACL's may be the best solution, I'm not too familiar with what you can and cannot do with them yet. Zeev -- Zeev Suraski <zeev@zend.com> CTO, Zend Technologies Ltd. http://www.zend.com/

« previous php.dev (#38194) next »