RE: Apache and home directories (file browser).

From: Shawn Mitchell (shawnm_at_iodamedia.net)
Date: 02/21/04

  • Next message: VA: "thanks - firewalling policy"
    To: "Freebsd-Isp" <freebsd-isp@freebsd.org>, "alan" <amd@headru.sh>
    Date: Fri, 20 Feb 2004 23:23:25 -0600
    
    

    It's just like any programming language. If you don't dot all of your i's
    and cross your 't's, then your open for something here and there.

    I'm not saying php-Nuke is bad, just that it's complicated enough, that
    chances are something's not double check here and there.

    Like any and ALL programming languages, YOU SHOULD NEVER TRUST YOUR INPUT.
    Check it, double check it, reverse it, check it again, and still don't trust
    it.

    my $0.02's worth (or $0.002 in England now)

    -----Original Message-----
    From: owner-freebsd-isp@freebsd.org
    [mailto:owner-freebsd-isp@freebsd.org]On Behalf Of alan
    Sent: Friday, February 20, 2004 2:13 PM
    To: freebsd-isp@freebsd.org
    Subject: Re: Apache and home directories (file browser).

    Please be aware that allowing uploads through php is quite insecure. A
    lot of php-Nuke hacks have been accomplished that way. google for
    security info on uploads through php.

    alan
    _______________________________________________
    freebsd-isp@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"

    _______________________________________________
    freebsd-isp@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"


  • Next message: VA: "thanks - firewalling policy"

    Relevant Pages

    • Re: Websites 101
      ... > I am presently attempting my first commercial site and was hoping I ... Google Groups, and search the archive of this group, for example ... PHP is, uhm, a very bad designed programming language which has its ... Altough learning a programming language takes a lot of time, ...
      (alt.internet.search-engines)
    • Re: JAVA and PHP
      ... requests to a server running PHP ... and return some parsable data to the Java program. ... I see nothing there that would exclude PHP from being a "programming language". ... you would probably have to say that "scripting languages" are ...
      (comp.lang.java.programmer)
    • Re: How to make mod_lisp faster than php?
      ... EW> slow because someone used the wrong programming language. ... ABCL isn't very fast by ... PHP scripts start from scratch for each request ... PHP was used to process data and upload it into SQL database. ...
      (comp.lang.lisp)
    • Re: C++ Compiler On FreeBSD
      ... PHP isn't really a programming language. ... for me it's just funny thing that needs several megs of RAM to display the ... and common footer. ...
      (freebsd-questions)
    • Enhancements to PHP -- Polar
      ... I like PHP a lot. ... It's my favorite programming language. ... that would convert the script into a Linux ELF binary or EXE. ... You still need the interpreter to be ...
      (comp.lang.php)