Re: PHP class files without <?php at the top
| From: | Yasuo Ohgaki | Date: | Mon, 09 Apr 2012 20:28:11 +0000 |
| Subject: | Re: PHP class files without <?php at the top | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-59545@lists.php.net to get a copy of this message | ||
Hi,
2012/4/10 Ángel González <keisial@gmail.com>:
> On 09/04/12 21:17, Yasuo Ohgaki wrote:
>> Please do not tell me that programmer should
>> learn not to, since it's not a protection but education.
> Hire a more competent programmer? If he writes such code,
> he will be completely unaware of the subtleties of XSS, or how
> SQL should be escaped, and his code is probably beyond
> "protection". You're better served by rewriting it.
I'm teaching at University on occasion.
Do you forget how you have learned languages?
>
>
>> If programmers/administrators could disable embed mode,
>> then systems will be protected from vulnerable codes.
> How do you enforce that the application you need doesn't rely on it?
>
> Note: 'education' is also forbidden as you restricted it in the
> previous question. :-)
>
Why do you insist while there is a systematic solution for it?
Regards,
--
Yasuo Ohgaki