4 ms·
I disagree that these problems are inherent to PHP. If the themes were written in almost any other language, people would still download themes or plug-ins and
by infinity 16y ago
I disagree that these problems are inherent to PHP. If the themes were written in almost any other language, people would still download themes or plug-ins and put it on their webspace. Many of the WordPress users are not experienced in coding for the web and some are not aware of the potential dangers that come with scripts from a shady source. They only get interested in security when their sites get owned. In the first place they just want to blog.
There are similar problems with widgets that people like to install in a sidebar or footer, like counters, clocks, ... There have been several cases where the widgets used a JavaScript hosted on a different domain, and later the JavaScript was changed to something that redirected visitors to infected sites. Here no PHP or any other server side language is involved. This problem is older than WordPress.
- JoachimSchipper 16y agoSorry, but who's talking about PHP here?
- telemachos 16y agoI think he meant to reply to lkbruner[1] but "missed": > Some of these problems are inherent to PHP [1]: http://news.ycombinator.com/item?id=2131095 http://news.ycombinator.com/item?id=2131095
- infinity 16y agoYes, actually I wanted to reply, but my answer ended up as a stand-alone comment. I'm sorry for this, if it caused some confusion.
- infinity 16y agoWhen the discussion started there were some remarks like this: >Some of these problems are inherent to PHP Also the availability of eval() and base64 encoding and decoding functions in PHP were blamed for the problems. You can find these statements if you read through the whole thread.
- troels 16y agoEvery comparable language has an eval statement or equivalent. And the base64 functions are quite practical have around if you should ever have to ... eh ... decode or encode in base64. The problem here is not with PHP, but with naïve users installing software from a dubious source.
- infinity 16y agoYes, this is similar to what I wrote above. And the problem is even older than PHP. For as long as I can think back there have always been people clicking every colorful link saying "Click here! It's FREE!" and "Download for Free!". Back then the nasty payload came from cracked software and games, stuff like boot sector viruses. I wouldn't put the blame for this on assembly language.