RE: [PHP-DEV] CVS Account Request

From: Date: Wed, 15 Nov 2000 21:44:13 +0000
Subject: RE: [PHP-DEV] CVS Account Request
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-38205@lists.php.net to get a copy of this message
At 00:37 16/11/2000, Rasmus Lerdorf wrote:
Do you guys remember the people who hacked apache.org? They did it just to show how easy it is, and if they weren't 'white hats', they could have easily injected bogus code into the most popular Web server in the world. PHP is the most popular opensource Web language in the world, and we shouldn't make it easier for hackers to get in. That was a completely separate situation. And nothing that has been mentioned here would do anything to prevent such an attack on PHP.
I didn't say it was. It was an example showing that the motivation is *THERE*. If you needed a clear proof, it's that. Other than that, there are no similarities. People can inject security bugs in the PHP CVS in much, much easier ways than the guys who hacked apache.org. The way things are right now, we'll practically give them this access on a silver platter. Zeev -- Zeev Suraski <zeev@zend.com> CTO, Zend Technologies Ltd. http://www.zend.com/

« previous php.dev (#38205) next »