Re: Exploits in PEAR?
| From: | Ian P. Christian | Date: | Wed, 27 Oct 2004 19:16:00 +0000 |
| Subject: | Re: Exploits in PEAR? | ||
| References: | 1 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-15168@lists.php.net to get a copy of this message | ||
On Wednesday 27 October 2004 18:40, Stowe, Nola wrote:
> My *network admin* guy is suddenly against PEAR for reasons he does not
> feel inclined to share with me. I guess reinventing the wheel is more fun
> (hey, at least its job security, huh?)
>
> Does anybody know of any particular exploits or security problems with
> using PEAR? specifially the DB, DB_DataObject, Services_Weather ???
Before I begin, I would like to point out I am not a PEAR developer, and I
only dive into PEARs code when I need to find out how something works, or
where the documentation is lacking.
As I'm sure you all know PEAR is a collection is libraries, and as such, the
application (scripts, website, whatever you prefered name is) is responsible
for passing information to this library.
I expect occasionally an issue might be found in some of these libraries that
might result in a secuity issue, however, as always, it is up to the
application developer to develop a site that sanatises all information before
passing it to the libraries provided by PEAR.
If you 'reinvent the wheel' and program some of these libraries from scratch,
who's to say you code will be better/more secure? Atleast with PEAR, there
is a community of developers and users to spot problems, fix security issues,
improve and update these libraries.
Essentially, in any project, time is money. Using PEAR speeds up application
development. Whilst there are some cases I wouldn't use PEAR (*very* high
usage sites, it's perhaps better to invent a lighter wheel ;) ), PEAR has,
and will continue to be a vital building block for most of my applications.
Personally, I would ask the network admin to better justify his choice as to
stopping the use of PEAR.
I hope this is of some help to you.
Kind Regards,
Ian P. Christian
http://www.pookey.co.uk