RE: [PHP] PHP Business Pack
| From: | James Moore | Date: | Tue, 12 Dec 2000 13:56:17 +0000 |
| Subject: | RE: [PHP] PHP Business Pack | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-29878@lists.php.net to get a copy of this message | ||
> > James,
> >
> > Security is probably the most important factor for some.
> >
> > How secure is PHP against it's rivals etc.
> >
>
> I'm missing something I guess.
>
> I agree that a language should provide access to security related
> information,
> but how can a language in itself be secure or insecure?
>
> It's the programs that are written in PHP that can be secure or insecure,
> but
> how a predicate like that can be applied to PHP I don't understand....
A language itself cannot be secure.. I can create an application in PHP,
JSP, ASP etc that will allow anyone full access to my computer to do
anything they want to (Then again I might want to do this) but there are
ways of making it possible for your apps to me MORE secure.
One example of this was the uploaded file thing that came up a few months
ago. (Read bugtraq and php-dev archives). Although the current PHP solution
was perfectly secure when coded well (see examples in the manual) it could
also become very unsecure when people wernt aware of what was going on. So
Zeev (IIRC) implemented a copy_uploaded_file() and is_uploaded_file function
(I think thats their names) to counteract this.
The point of this was to make writing secure scripts easy, and that is
somthing that PHP does VERY well. We very rarely appear on bugtraq
legitimatly. The only two I remeber in the past two years are that one and
one a few weeks ago about PHP3 and apache1.3.6 which none of the dev team
could recreate so is likely to be misconfiguration or mis compilation by the
reporter which should not have happened on a production server with a semi
capable sys admin who reads the docs. Anyway Im diverging, but there are
lots of tools such as those mentioned above to make security in PHP easy as
well as allowing quick codeing and powerful applications, we will see even
more of this when the Apache 2.0 and related SAPI are complete with a decent
(hopefully) secure version of safe mode which at the moment isnt great.
James