RE: [PHP] PHP Business Pack

From: Date: Tue, 12 Dec 2000 13:56:17 +0000
Subject: RE: [PHP] PHP Business Pack
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-29878@lists.php.net to get a copy of this message
> > James, > > > > Security is probably the most important factor for some. > > > > How secure is PHP against it's rivals etc. > > > > I'm missing something I guess. > > I agree that a language should provide access to security related > information, > but how can a language in itself be secure or insecure? > > It's the programs that are written in PHP that can be secure or insecure, > but > how a predicate like that can be applied to PHP I don't understand.... A language itself cannot be secure.. I can create an application in PHP, JSP, ASP etc that will allow anyone full access to my computer to do anything they want to (Then again I might want to do this) but there are ways of making it possible for your apps to me MORE secure. One example of this was the uploaded file thing that came up a few months ago. (Read bugtraq and php-dev archives). Although the current PHP solution was perfectly secure when coded well (see examples in the manual) it could also become very unsecure when people wernt aware of what was going on. So Zeev (IIRC) implemented a copy_uploaded_file() and is_uploaded_file function (I think thats their names) to counteract this. The point of this was to make writing secure scripts easy, and that is somthing that PHP does VERY well. We very rarely appear on bugtraq legitimatly. The only two I remeber in the past two years are that one and one a few weeks ago about PHP3 and apache1.3.6 which none of the dev team could recreate so is likely to be misconfiguration or mis compilation by the reporter which should not have happened on a production server with a semi capable sys admin who reads the docs. Anyway Im diverging, but there are lots of tools such as those mentioned above to make security in PHP easy as well as allowing quick codeing and powerful applications, we will see even more of this when the Apache 2.0 and related SAPI are complete with a decent (hopefully) secure version of safe mode which at the moment isnt great. James

« previous php.general (#29878) next »