[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: PHP security issues? (Thanks)



David Clymer wrote:

On Sat, 2006-04-08 at 21:34 -0700, Marc Shapiro wrote:

I recently installed php4 (4.3.10-16) since I am about to bite the bullet and pay for hosting of my web-site and the hosting service (1&1.com) only allows php3, php4, or php5 with its least expensive service. I am now going to teach myself php so that I can make use of the service if need be. I keep seeing posts, however, about security issues with "badly written" php scripts. Can someone point me to some info explaining what the security issues are so that I don't end up writing scripts that will be a security risk.


I think a PHP mailing list would be the appropriate place for this
question, not debian-user.

For secure programming tips, go to google, type in "writing secure php"
and click "I'm feeling lucky."


Thanks for this link. I will check it out (and the other articles that it links to in the series) and then go on to a PHP mailing list if I feel that I need more info.

If you have to learn a language, you might want to think about using
python-hosting.com or some other place that supports Django
(http://djangoproject.com) and RubyOnRails (http://rubyonrails.org) as
well as PHP. IMHO, PHP is one of the uglier languages out there. These
two frameworks are written in much more beautiful/powerful languages
(python and ruby, respectively), and take care of a lot of the tedium
involved in developing web apps - Django especially.

As I said, above, PHP is the only language allowed for the hosting services that I am thinking of using. It is not worth it for my site to spend more on a different host, or for the more expensive options at 1&1.com. Other than the lack of perl and python support, the Beginner package provides much more than I could need, so it is not worth paying 60% more for a higher level package.


-davidc



--
Marc Shapiro

No boom today. Boom tomorrow. There's always a boom tomorrow.
What?! Look, somebody's got to have some damn perspective around here.
Boom. Sooner or later ... boom!

- Susan Ivanova: B5 - Grail



Reply to: