From: Andreas Schwarz Date: 2003-05-07T02:08:38+09:00 Subject: Re: Why is PHP so popular? What can we learn from the PHP camp? Paul DuBois wrote: > At 21:46 +0900 5/6/03, Andreas Schwarz wrote: >>Paul DuBois wrote: >>> At 6:01 +0900 5/6/03, Andreas Schwarz wrote: >>>>Aredridel wrote: >>>>> PHP was less designed than just kludged together. >>>> >>>>The language itself is VERY ugly, this doesn't need a discussion, and >>>>you could fill a book with the history of security problems in PHP. >>> >>> That's an easy bandwagon to jump on, and (though you may be an exception), >>> I'd guess that the majority of people who would be willing to throw out >>> a remark like that couldn't name more than a couple of such exploits >>> without looking them up. >> >>I'm not only talking about exploits like buffer overflows, but also >>about the concept of the language which makes (or made) it so easy to >>write 'dirty' and dangerous code (GET-Variables registered in global >>namespace etc.). > > Could you explain this a bit more? I'm not clear on why having a > variable be global makes it more of a security risk [...] > Having request variables directly map onto script variables through > the register_globals directive *is* a security risk, because it allows > an attacker to set arbitrary variables in your script merely by naming > them on the request URL. This is what I meant. It is now disabled in the default distribution, but many webhosters still use register_globals because the users don't want to change their scripts. >>BTW: can mod_ruby be used on shared servers like mod_php? > > I'm not sure why sharing a server would preclude use of mod_ruby... For the same reasons why mod_php needs a "safemode": because all scripts run under the same uid?