4 ms·
wordpress is in php wikipedia is in php facebook is in php flickr is in php photobucket is in php need i say more?
by finalight 12y ago
wordpress is in php
wikipedia is in php
facebook is in php
flickr is in php
photobucket is in php
need i say more?
- Spooky23 12y ago> wordpress is in php That pretty much makes the point. 194 vulnerabilities in Wordpress with CVEs in 2014. http://www.cvedetails.com/vulnerability-list/vendor_id-2337/product_id-4096/Wordpress-Wordpress.html http://www.cvedetails.com/vulnerability-list/vendor_id-2337/...
- iancarroll 12y agoI would argue it is the developer writing the code, not the language it's written in.
- frabcus 12y agoTools can help developers write safer code. Yes, a good developer can write safe code in bad environment. But an average developer writes safer code in a good environment.
- pbhjpbhj 12y agoThat list appears to include CVE going back to 2006 at least. I count 17 in 2014, the highest rated of which is an arbitrary code exectution (CVE-2014-5203) rated 7.5. Not sure number of disclosed flaws is a good metric to look at, whether it's high or low.
- IshKebab 12y agoArbitrary code execution is pretty damn bad. Anyway he wasn't just counting vulnerabilities. Wordpress is renowned for its terrible security (or plugins with terrible security often).
- pbhjpbhj 12y agoI avoided making any value judgement on purpose - you can't really do that off-the-cuff. Looking at the reports (linked here, [0]) it concerns hash checks on serialised widgets. The apparent vulnerability was reported by the Wordpress security team and reported as being hard to actually make work - I can't find a PoC or any actual exploit reports. It seems based on [1] that a fix was submitted 2 months before the report and made available to automatic updaters a few days prior (? I'm not sure how the reporting dates and such work here really, on a superficial view that's right though the bug is 2014-08-13 and the fix 2014-06-08 with the report of the update [2] coming 2014-08-06). So, whilst yes an arbitrary code execution is severe one that is fixed before it's made public and without any clear way to exploit it is perhaps less of an issue than it first appears. But then of course the number of installs mean you can very likely find vulnerable installs in the wild even today. TL;DR simple statistics don't really seem to work well in providing a proper view of comparative levels of security of web apps. [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5203 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5203 [1] https://core.trac.wordpress.org/changeset/29389 https://core.trac.wordpress.org/changeset/29389 [2] https://wordpress.org/news/2014/08/wordpress-3-9-2/ https://wordpress.org/news/2014/08/wordpress-3-9-2/
- regularfry 12y agoYes.
- benbristow 12y agoI thought Facebook made their own PHP fork type of language.
- adrusi 12y agoyeah, to say Facebook is written in PHP is misleading. Facebook was originally written in PHP. Now it runs on the HHVM, which foregoes supporting the dangerous parts of the PHP stdlib, and offers better performance (fixing the two biggest problems with PHP). As I understand, much of their new code is written in Hack which interoperates with their legacy PHP code but supports gradual typing and other safety features (and some niceties). Facebook is written in PHP, but they have invested a lot into making their PHP not be PHP.