Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
PHP Security From The Inside
Federico Biancuzzi, 2007-02-05

Stefan Esser is the founder of both the Hardened-PHP Project and the PHP Security Response Team (which he recently left). Federico Biancuzzi discussed with him how the PHP Security Response Team works, why he resigned from it, what features he plans to add to his own hardening patch, the interaction between Apache and PHP, the upcoming "Month of PHP bugs" initiative, and common mistakes in the design of well-known applications such as WordPress.

Comments Mode:
PHP Security From The Inside 2007-02-05
Anonymous (1 replies)
PHP Security From The Inside 2007-02-07
PHP Application Dev. (3 replies)
Re: PHP Security From The Inside 2007-02-08
Anonymous
Re: PHP Security From The Inside 2007-02-15
Anonymous
> It's unfortunate that Stefan has decided to put at risk a large
> portion of websites on the Internet.

Actually its unfortunate that *PHP* has done this *and* mistreated someone who was/is trying to make it a viable option.

Plus this "large portion of websites" you refer to are to blame since they use PHP in the first place.

IMHO, *anything* is better than PHP if for no other reason because of the head-in-the-sand security that has caused so many problems for so many sites and admins and the attitude they have toward doing it right. (IE PHP will never do it right and is therefore not an option for any serious application. In fact web servers without PHP is starting to be a selling point in the hosting industry.)

Not to mention the horrid state its in due to it being a ball of glue that piece meals real tools together with no rhyme or reason.

Stefan has done a lot that has probably saved *you* more often than not since you apparently blindy use PHP scripts with full trust in their absolute infalibility.

You should thank him not berate him. Its your kind of clueless "I'm so smart" attitude that makes PHP so incredibly stupid.

> Since he is aware of the bugs, he most likely knows the fixes
> as well. Will he be posting the fixes? That would benefit security...

Good god man did you even *read* the article? He's been doing just that for *years* and all they do is abuse him because finds their idiotness? The essence of PHP.

PHP and ignorance is the enemy not Stefan.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/432/34345#34345
Re: PHP Security From The Inside 2007-02-20
Don Hopkins
Blame others, hype yourself 2007-02-08
Sebs (2 replies)
Re: Blame others, hype yourself 2007-02-08
Anonymous (1 replies)
Re: Re: Blame others, hype yourself 2007-02-15
Anonymous (1 replies)
Re: Blame others, hype yourself 2007-02-13
Anonymous
PHP Security From The Inside 2007-02-20
brokenToy
This is highly irresponsible 2007-02-20
Paul Hickman (2 replies)
Re: This is highly irresponsible 2007-02-20
Mark Zein
Re: This is highly irresponsible 2007-02-20
John Carmichael (1 replies)
Re: Re: This is highly irresponsible 2007-02-21
Anonymous (1 replies)
PHP Security From The Inside 2007-08-13
Anonymous







 

Privacy Statement
Copyright 2007, SecurityFocus