Re: Exploits in PEAR?

From: Date: Thu, 28 Oct 2004 09:43:44 +0000
Subject: Re: Exploits in PEAR?
References: 1  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-15183@lists.php.net to get a copy of this message
Nola Stowe wrote:
My *network admin* guy is suddenly against PEAR for reasons he does not feel inclined to share with me. I guess reinventing the wheel is more fun (hey, at least its job security, huh?)
I do code auditing for a very large UK organisation - who use PEAR extensively partly because it is audited, in the usual open source way :) The only thing to audit for DataObjects is code using the query() and whereAdd() methods, look for variables used in as arguments that have not been sanitized - Generally, though these tools seriously reduce the scope of auditing necessary on a usual PHP application. If they are that way inclined, ask him who audit's his network scripts (and see if they can audit the work you provide :) Regards Alan
Does anybody know of any particular exploits or security problems with using PEAR? specifially the DB, DB_DataObject, Services_Weather ???
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><> The information in this email and any attachments may contain confidential information that is intended solely for the attention and use of the named addressee(s). This message or any part thereof must not be disclosed, copied, distributed or retained by any person without authorization from the addressee. If you are not the intended addressee, please notify the sender immediately, and delete this message. <><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>


« previous php.pear.general (#15183) next »