3 ms·
>> A full-stack PHP framework delivered as a C-extension! > I mean, I've can't even begin to imagine how insecure that awful combination of insecure by default
by Ardren 5y ago
>> A full-stack PHP framework delivered as a C-extension!
> I mean, I've can't even begin to imagine how insecure that awful combination of insecure by default languages is.
What is inherently insecure about PHP? Or Phalcon? Do they have vulnerabilities that other C programs don't have?
- beermonster 5y agoPHP itself used to have a poor security track record. Not sure what the situation is these days? I guess this[1] is one place to start. C programs are often exposed to classes of vulnerability owing to weaker safety guarantees see[2] [1] https://wiki.php.net/cve https://wiki.php.net/cve [2] https://msrc-blog.microsoft.com/2019/07/22/why-rust-for-safe-systems-programming/ https://msrc-blog.microsoft.com/2019/07/22/why-rust-for-safe...
- topspin 5y agoVulnerabilities in PHP appear regularly. A mass of them for PHP 7.x appeared in my inbox yesterday: https://ubuntu.com/security/notices/USN-5006-1 https://ubuntu.com/security/notices/USN-5006-1
- lloydatkinson 5y agoI should think a quick google of "C string vulnerability" will answer your question.
- lloydatkinson 5y agoAh yes, the C users got triggered.