5 ms·
It's true and is the reason why so many PHP powered CMS are so insecure, how many times do you hear about a new wordpress exploit?
by mariocesar 12y ago
It's true and is the reason why so many PHP powered CMS are so insecure, how many times do you hear about a new wordpress exploit?
- UnoriginalGuy 12y agoIt really has nothing to do with PHP. Changing the language or framework wouldn't inherently change the design. e.g. http://www.cvedetails.com/vulnerability-list/vendor_id-26/product_id-11116/Microsoft-Sharepoint-Server.html http://www.cvedetails.com/vulnerability-list/vendor_id-26/pr...
- tankenmate 12y agoHaving said that PHP does make it very hard to run each interpreter process as the user it is doing work on behalf of. Some of the best systems out there run each user's process under it's own uid:gid (or equivalent), and each user has their own filespace and/or database. Obviously this pushes the separation issues down to the OS kernel rather than in the app, but most widely used OS kernels get at least an order of magnitude more, most of the time several orders more, testing for these user separation security features. NIH, re-inventing the wheel and all that.
- drzaiusapelord 12y agohow many times do you hear about a new linux kernel exploit? Pretty much everything is insecure. Writing things in not-php isn't the magical fix you seem to think it is.
- moe 12y agoWhat an absurd comparison... The linux kernel has 16 million lines of code, Wordpress has 300k. Yet Wordpress[1] has had nearly as many security vulnerabilities as the kernel[2]; 194 vs 257 exploits. Wordpress is one of the most exploited software packages ever created. It is the textbook example of bad programming. Just mentioning the kernel when talking about Wordpress is pretty ridiculous. [1] http://www.cvedetails.com/vulnerability-list/vendor_id-2337/product_id-4096/Wordpress-Wordpress.html http://www.cvedetails.com/vulnerability-list/vendor_id-2337/... [2] http://www.cvedetails.com/vulnerability-list/vendor_id-33/product_id-47/cvssscoremin-7/cvssscoremax-7.99/Linux-Linux-Kernel.html http://www.cvedetails.com/vulnerability-list/vendor_id-33/pr...
- jordanlev 12y agoI am no fan of wordpress, and I agree that it is a textbook example of bad programming... but it is also a textbook example of good community management and success at empowering non-programmers to have their own web presence. And I believe that the amount of exploits has as much to do (if not moreso) with its sheer popularity as it does with the code.
- maratd 12y ago> Wordpress is one of the most exploited software packages ever created. Hyperbole much? It's one of the most popular software packages installed on the web. It's not surprising it has a lot of eyes on it.
- moe 12y agoThis has nothing to do with eyes. Dozens of other packages have a much larger install base than Wordpress. Wordpress has 32(!) CVE's tagged with "Exec Code" (remote code execution) alone. The last one a mere 6 months old. If you know another project that comes even remotely close to that then I'd be genuinely curious which one that would be?
- maratd 12y ago> This has nothing to do with eyes. Yeah, it does. You can write a crappy piece of software that nobody uses and because nobody has interest in it, it has no known security issues! Big deal. I'm not saying that Wordpress has a great code-base or that there's no correlation, but that popularity is a substantial variable in that equation. > Dozens of other packages have a much larger install base than Wordpress. Name one web based software suite that's installed more often.
- moe 12y agoName one web based software suite that's installed more often. What does "web based" have to do with anything? Do you think SSH, Postfix, nginx, Apache & Co don't get the same amount of scrutiny? Each of them has a significantly larger install base than Wordpress.