6 ms·
Meaning they’re installing PHP on all routers to support Nextcloud? Not the expert here but that doesn’t sound too secure to me.
by hazelnut 8y ago
Meaning they’re installing PHP on all routers to support Nextcloud? Not the expert here but that doesn’t sound too secure to me.
- tomcooks 8y agoPHP can be secure
- EvangelicalPig 8y agoMost people's "PHP is inherently insecure" perception comes from projects like phpBB 2.x circa a decade ago and the shared hosts (still?) running an ancient version of PHP.
- paulie_a 8y agoAnd WordPress, drupal and honestly every other php project custom or open source. PHP needs to go away.
- washadjeffmad 8y agoCareful, there are a lot of WP, Drupal, and PHP devs here, and they make up a much bigger chunk of the front end developer pool than you'd expect post-2000s. And from sitting in on a lot of leadership meetings, they're one of the few groups that perpetually seems to be concerned with something they depend on sunsetting. As long as they're passing with ISO, I just stay out of it.
- paulie_a 8y agoThat's fine if they are upset. Php is a scourge on the internet. If php on the server and Java on the desktop were wiped out. The internet would be a better place.
- tomcooks 8y agoAs opposed to? Le JS framework-du-jour? /s
- c487bd62 8y agoI'll take PHP spaghetti over JS any day
- gmemstr 8y agoPHP is fine, no software is bug free, especially when it accepts external input. Drupal, WordPress etc are huge so there's definitely a lot of chances for things to sneak in, but PHP itself can't be 100% to blame.
- paulie_a 8y agoThey are low hanging fruit to exploit. Considering drupal specifically, and the massive history of WordPress (oh I can grab root passwords because of a massively deployed image slider) An attacker is thinking it's Christmas morning. And yes it is because they are PHP. It's unsafe under any circumstances. Php is a go-to route of getting a shell.
- prophesi 8y agoIt's trivial to look up what version of WordPress/Drupal/etc a site is running, and looking up that version's vulns. The issue is that sites don't keep their CMS up-to-date. Not because it's PHP. Every CMS, regardless of language, faces this issue.
- paulie_a 8y agoIt's just that some CMS is based on php and they consistently have far more vulnerabilities than non PHP ones. PHP is crap. It always has been, it will continue to be. I honestly can't imagine a building a production project from that garbage language in this day and age.
- prophesi 8y agoIn this day and age, you'd use a framework like Laravel or CakePHP, which are a joy to work in. And the only reason you see more vulnerabilities for CMS's written in PHP is because the most popular CMS's (Wordpress, Joomla, Drupal) are all written in PHP. We'd see the same thing happen regardless of the language (except maybe Ada or Rust. They do a good job at stopping you from shooting yourself in the foot).
- JoshMnem 8y ago> the shared hosts (still?) running an ancient version of PHP. Still 80%+ of PHP sites. https://w3techs.com/technologies/details/pl-php/all/all https://w3techs.com/technologies/details/pl-php/all/all https://www.linkedin.com/pulse/ticking-php-time-bomb-martin-wheatley/ https://www.linkedin.com/pulse/ticking-php-time-bomb-martin-...
- adventured 8y agoNo. That w3tech link is not properly separating out the versions by age. 5.6 isn't an ancient version of PHP for example; 5.1 is. 5.6.36 was released in April 2018; 5.6 was released in 2014. 5.1 was released in 2005 by contrast. There's nothing terribly wrong with running 5.6x if you have a good reason to do so (eg legacy), other than that the performance sucks compared to 7.2. You can dig further into the w3tech numbers here: https://w3techs.com/technologies/details/pl-php/5/all https://w3techs.com/technologies/details/pl-php/5/all Nobody is using 5 or 5.1. The majority of all PHP installations are using more modern versions, either 5.6x or 7.x.
- JoshMnem 8y agoPHP 5.6 is reaching the end of security updates in four months and 80% of PHP sites are still running it (or lower). https://secure.php.net/supported-versions.php https://secure.php.net/supported-versions.php
- zaphar 8y agoSure, anything an be secure. PHP just makes is comically easy to be insecure.
- prophesi 8y agoHere's a good start: https://paragonie.com/blog/2017/12/2018-guide-building-secure-php-software https://paragonie.com/blog/2017/12/2018-guide-building-secur... The big issue with PHP's security is that there are a lottt of old guides and stackoverflow answers out there with terrible, unsafe practices.
- hazelnut 8y agoI see, thanks for the explanation
- Walkman 8y agoThey are actually know what they are doing. I think they have a full time security guys and also have a bug bounty as others have mentioned.