|
From: John v. V. <joh...@ya...> - 2003-06-25 21:49:54
|
Hi all, Heiko's email about the mistakes in security pointed out problems in PHP. I have been fooling around with AmphetaDesk, a RSS news tool which is in perl and has a tiny perl http server. Webmin, also written in perl, is in wide commercial use, has significant secturity and has a perl httpd server. Python is nice but I never used it because it uses white spaces as part of it OO implementation, which is scary when debugging under pressure. As I mentioned to Bruce it is high time for a new admin scripting language though I am on advocating DL... I am in Utah right now, at a big party in the mountains.. big 20,000 people :) John http://www.itworld.com/AppDev/4072/020301phpflaws/ PHP security flaws affect 1 million Web sites ITworld.com 3/1/02 About 1 million Web sites are vulnerable to attack through recently discovered flaws in the popular PHP (Personal Home Page) scripting language, Web server information firm Netcraft Ltd. said Friday. Advertisement On this topic Data Management Strategies. Sign up Now! New Strategies to Effective Business Continuity An Architecture for Next-Generation Business Intelligence Hole in PHP could give attacker server control Server-side HTML hell Open source Web application development tools and languages One million may seem a high number, but it is much lower than the numbers suggested in security warnings that have been sent out this week, Netcraft Director Mike Prettejohn said. "A system is only vulnerable when PHP is actually used on a Web site, not when it is installed on the server. Current advisories have not made that especially clear," he said. About 8.4 million Web sites support a vulnerable version of PHP, but only about 1 million of those actually use the scripting language on Web pages, which is what makes them vulnerable, according to Prettejohn. --- Bruce Smith <bw...@ar...> wrote: > > > And according to boa.org, thttpd is "very similar to Boa", and I see we > > > already have thttpd in DL... > > > > So a step closer, > > Why was thttpd originally added to DL? > > > except if John really needs the real apache. > > I hope not. Apache is HUGE compared to boa & thttpd: > > http://www.acme.com/software/thttpd/benchmarks.html > > One other advantage of thttpd over boa is thttpd supports "basic auth", > and boa doesn't. > > > > PHP can be compiled as a standalone CGI program, so it should work with > > > any web server that supports CGI. > > > > I guess Axis did choose PHP3 because of the lower memory footprint > > than PHP4. > > Could be. We should probably go with PHP4 so we are sure to have the > latest security updates. > > - BS > > > > > ------------------------------------------------------- > This SF.Net email is sponsored by: INetU > Attention Web Developers & Consultants: Become An INetU Hosting Partner. > Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission! > INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php > _______________________________________________ > Devil-linux-develop mailing list > Dev...@li... > https://lists.sourceforge.net/lists/listinfo/devil-linux-develop > > ===== CXN, Inc. Contact: jo...@th... President, The Linux Society http://groups.yahoo.com/group/linux-society linux society distro -> http://www.thinman.com/eLSD/readme ThinMan is a registered trademark of CXN, Inc __________________________________ Do you Yahoo!? SBC Yahoo! DSL - Now only $29.95 per month! http://sbc.yahoo.com |