Re: PHP Business Pack

From: Date: Tue, 12 Dec 2000 13:41:32 +0000
Subject: Re: PHP Business Pack
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-29877@lists.php.net to get a copy of this message
Sander, If you take a look at the PHP web site you will see that PHP 4.0.3pl1 was released to fix a number of security related problems. One problem with PHP allowed users to override admin_value's and admin_flag's, this was fixed quickly by the PHP developers and unless you really knew what you where doing it wasn't too serious. Obviously I can't go into too much detail here but this shows just how vunerable a system can be if adequate security measures are not implemented from the start. Every program written has some form of security hole in it, whether it be a web server or a development environment, they are still programs written by human beings who occasionally make mistakes, it's a fact of life, no one is perfect and all software has bugs of some sort. I could be in for a rough time with some people over my statement but it's true. No matter how well you program a system there will always be something that doesn't work exactly the way you intended. On the security issue, I would like to know if PHP can provide user identification and authentication, can I access an SSL enabled web server with PHP, are there encryption functions with PHP for use with security. The answer to all of these questions I know is yes. I'm sure there are hundreds more security related questions but I really don't have the time. Andy Woolley andy@databasewatch.com ----- Original Message ----- From: "Sander Pilon" <sander@3dnews.net> To: "Andy Woolley" <andy@milonic.com>; "James Moore" <jmoore@php.net>; "Php-General" <php-general@lists.php.net> Sent: Tuesday, December 12, 2000 12:43 PM Subject: RE: [PHP] PHP Business Pack > > James, > > > > Security is probably the most important factor for some. > > > > How secure is PHP against it's rivals etc. > > > > I'm missing something I guess. > > I agree that a language should provide access to security related > information, > but how can a language in itself be secure or insecure? > > It's the programs that are written in PHP that can be secure or insecure, > but > how a predicate like that can be applied to PHP I don't understand.... > > -S > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.general (#29877) next »