Re: Deprecate PHP's short open tags, again
| From: | Robert Korulczyk | Date: | Wed, 14 Aug 2019 10:34:44 +0000 |
| Subject: | Re: Deprecate PHP's short open tags, again | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-106596@lists.php.net to get a copy of this message | ||
W dniu 14.08.2019 o 12:09, Reinis Rozitis pisze:
> It's questionable that a misconfigured environment is a "security" risk caused
> by language rather than ignorance of the administrator.
This is not about misconfigured environment. This is about accidental usage of *language* feature,
which *by design* can lead to code leaks (so
application bug, not misconfigured environment). Clearly not a language problem that it has
dedicated feature to shoot yourself in the foot...
> On that matter you could ask why are all the exec/passthru/proc_open etc functions/features are
> allowed by default while every other guide on
hardening web suggests those to be disabled (added to disable_functions)?
These methods have their purpose (pretty important BTW), short open tags is just "don't
use it!!!" feature.
Regards,
Robert Korulczyk