3 ms·
It usually get's to my nerve when people jump in the "PHP is inferior language because I decided so" bandwagon, but this kind of security strategy ind of gives
by skeptical 15y ago
It usually get's to my nerve when people jump in the "PHP is inferior language because I decided so" bandwagon, but this kind of security strategy ind of gives some base for such criticism.
Disable external execution functions, eval, disable disable, disable. It appears to me that this is following the approach of disabling everything and nothing, then start coding without any security concerns, because you 'secured your PHP'.
I'm not a security obsessed person, but after hearing so much fuss about PHP lack of security I headed up to milw0rm a few years ago to see what it was all about. To my surprise (not so much) all the exploits were based on non sanitized user data.
Why would you use user data without sanitizing it? Why would you protect yourself against a file the hacker uploaded? (they should not have uploaded it in the first place)
Why would you feed exec, eval, etc with potentially dangerous content?
If a programmer is stupid enough to do so, disabling such functions won't prevent him/her from screwing up big time some other way.
My advice: write proper applications with proper standard security in mind. It's not that hard.
- infinity 15y agoThe problem of working with unsanitized user input is not specific to PHP, this has been a problem with other server side scripting languages as well. Here is an ancient example: NT Web Technology Vulnerabilities, written by rain.forest.puppy, Phrack Magazine Volume 8, Issue 54 Dec 25th, 1998. http://www.phrack.org/issues.html?issue=54&id=8#article http://www.phrack.org/issues.html?issue=54&id=8#article This is one of the oldest articles on SQL injection I know of.
- skeptical 15y agoThat's what I am trying to say. Common security practices will put you out of danger. I'm confused why we should have recipes to 'secure PHP'. Why don't the regular security measures simply apply? My guess is that many don't know what they are so they apply follow 'secure PHP' guides and feel safe, though they are not.
- ars 15y agoMan, I so wish I had published or even just posted it on a newsgroup (usenet). I discovered/thought of SQL injection in 1996 (with ColdFusion code), but my boss refused to let me disclose it to anyone (I was young then and actually listened to him). He was going to do some big conference or something on the subject and drum up new business, but nothing ever came of it.