Re: Is PHP a security risk?

From: Date: Mon, 31 Jul 2000 22:51:04 +0000
Subject: Re: Is PHP a security risk?
References: 1  Groups: php.windows 
Request: Send a blank email to php-windows+get-1437@lists.php.net to get a copy of this message
On 4 Jul 2000 13:00:34 -0700, azoldi@yahoo.com (Arpad Zoldi) wrote: >Hello, > >I have a question. >I am creating a web-site which needs to access a >Database and retrieve and display information. >The alternatives on the server side for me where Java >Servlets (and JSP) and PHP. >I now Java well, I have experience with servlets but I >have chosen PHP because I wanted to learn PHP and I >think the development time in PHP is shorter. > >Now, the web-hosting company has NT and IIS (this was >not my choice). >PHP works with IIS, so I thought this should not be a >problem. I asked them to install PHP. The first answer >was: What is PHP? > >I explained and sent them to the web-site and asked >them, please, could you install PHP. >The answer was: they don't support PHP due to security >risks. > >I think that is silly. I do not see PHP more a >security risk than any other >server-side script or interpreter. From their point of >view, the only security problem which I could imagine >is in the PHP interpreter itself, but that's a >different story. In this case they don't trust the >people who created PHP and it has to do with the >open-source nature of PHP. > >My question for you is: >how do I convince them that PHP is not a security >risk? > >The first thing that came to my mind was to send to >them a list of big >web-sites using PHP. But I could not find any really >big names, only >w3c.org (which is quite big I admit) but after a first >glance I did not >find any phpscripsts there. >Anyone knows some well-known sites using PHP? > >All suggestions are welcome. >Regards, > Arpi If they are worried because it open-source, tell them to look over the source code themselves and try to find a security risk. If they can't satisfactorily examine the source code, In my opinion, they aren't really qualified to be Admins in the first place. JasonWP

« previous php.windows (#1437) next »