From: Rafael 'Dido' Sevilla Date: 2002-11-24T14:56:34+09:00 Subject: Re: Ruby/PHP security On Sun, Nov 24, 2002 at 09:49:00AM +0900, Ted wrote: > Someone made a comment (I paraphrase) like "PHP can do it, but with > complete insecurity", and opined that Ruby is more secure than PHP. > > Can someone elaborate? The only reason I can think of why anyone would say that PHP is less secure than Ruby or Perl for CGI work is that PHP does not have taint checking, as far as I can see, but I'd hardly call that "complete insecurity". If you're careful in writing all checks for postdata, cookies, and all that, you can write a secure PHP script that does careful checking and a totally insecure Ruby script with taint checking on that has untainting code similar to: tainted =~ /(.*)/ untainted = $1 or something similarly ineffectual. -- Rafael R. Sevilla +63(2)8123151 Software Developer, Imperium Technology Inc. +63(917)4458925