Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
padraicb
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
padraicb
13y ago
1) Agreed. 2) Citation? PHP is extremely popular so it has more insecure code in comparison to Ruby. Also Rails isn't above multiple security vulnerabilities per year so I don't see how Wordpress (which incidentally is an extremel
2.
▲
PHP RFC: Consistent Escaping Functionality For Killing XSS
(blog.astrumfutura.com)
1 points
by
padraicb
14y ago
|
0 comments
3.
▲
PHP Security, Authorative Knowledge and Combining Forces
(blog.astrumfutura.com)
1 points
by
padraicb
14y ago
|
0 comments
4.
▲
PHP Security: Default Vulnerabilities and Security Omissions
(blog.astrumfutura.com)
1 points
by
padraicb
14y ago
|
0 comments
5.
▲
by
padraicb
14y ago
Problem with HTML escaping by default - it's not all HTML escaping. Javascript strings need to be JS escaped, sometimes escaped by HTML as a second (or even first) step to complete the correct encoding needed to avoid XSS for the specific c