Another PHP vulnerability?
Posted Jul 15, 2005 17:32 UTC (Fri) by
ajross (subscriber, #4563)
In reply to:
Another PHP vulnerability? by uravanbob
Parent article:
Firefox marketing site hacked (News.com)
To be fair, I'm no PHP expert. Nonetheless, it seems to me that that
other comparable languages (Perl, Python, Ruby) have not, in fact,
been the subject of the number (or severity) of security flaws that
have been exhibited by PHP over the past few years.
While it's certainly true that there are no silver bullets for
security, it is not a corrolary that all software is equally secure.
In particular, some packages (like sendmail and wuftpd, which I
mentioned earlier) have had a history of such common and severe
security flaws that they have largely been dropped by the community in
favor of other implementations.
Basically, I was wondering aloud whether this point has been reached
by PHP. Feel free to prove me wrong, but also be open minded to the
other, potentially more secure options available.
(
Log in to post comments)