Re: PHP Business Pack
| From: | Andy Woolley | Date: | Tue, 12 Dec 2000 13:41:32 +0000 |
| Subject: | Re: PHP Business Pack | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-29877@lists.php.net to get a copy of this message | ||
Sander,
If you take a look at the PHP web site you will see that PHP 4.0.3pl1 was
released to fix a number of security related problems. One problem with PHP
allowed users to override admin_value's and admin_flag's, this was fixed
quickly by the PHP developers and unless you really knew what you where
doing it wasn't too serious.
Obviously I can't go into too much detail here but this shows just how
vunerable a system can be if adequate security measures are not implemented
from the start.
Every program written has some form of security hole in it, whether it be a
web server or a development environment, they are still programs written by
human beings who occasionally make mistakes, it's a fact of life, no one is
perfect and all software has bugs of some sort.
I could be in for a rough time with some people over my statement but it's
true. No matter how well you program a system there will always be something
that doesn't work exactly the way you intended.
On the security issue, I would like to know if PHP can provide user
identification and authentication, can I access an SSL enabled web server
with PHP, are there encryption functions with PHP for use with security. The
answer to all of these questions I know is yes. I'm sure there are hundreds
more security related questions but I really don't have the time.
Andy Woolley
andy@databasewatch.com
----- Original Message -----
From: "Sander Pilon" <sander@3dnews.net>
To: "Andy Woolley" <andy@milonic.com>; "James Moore"
<jmoore@php.net>;
"Php-General" <php-general@lists.php.net>
Sent: Tuesday, December 12, 2000 12:43 PM
Subject: RE: [PHP] PHP Business Pack
> > James,
> >
> > Security is probably the most important factor for some.
> >
> > How secure is PHP against it's rivals etc.
> >
>
> I'm missing something I guess.
>
> I agree that a language should provide access to security related
> information,
> but how can a language in itself be secure or insecure?
>
> It's the programs that are written in PHP that can be secure or insecure,
> but
> how a predicate like that can be applied to PHP I don't understand....
>
> -S
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>