Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #4247 > unrolled thread
| Started by | "M. Strobel" <sorry_no_mail_here@nowhere.dee> |
|---|---|
| First post | 2012-01-07 13:15 +0100 |
| Last post | 2012-01-08 17:38 -0500 |
| Articles | 20 — 8 participants |
Back to article view | Back to comp.lang.php
Lilupophilupop "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-07 13:15 +0100
Re: Lilupophilupop Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-07 08:15 -0500
Re: Lilupophilupop Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2012-01-07 18:27 +0100
Re: Lilupophilupop "J.O. Aho" <user@example.net> - 2012-01-07 18:52 +0100
Re: Lilupophilupop Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-07 16:02 -0500
Re: Lilupophilupop "Peter H. Coffin" <hellsop@ninehells.com> - 2012-01-10 18:31 -0600
Re: Lilupophilupop "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-11 09:29 +0100
Re: Lilupophilupop Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-11 08:42 -0500
Re: Lilupophilupop Erwin Moller <erwinmollerusenet@xs4all.nl> - 2012-01-11 15:23 +0100
Re: Lilupophilupop Gregor Kofler <usenet@gregorkofler.com> - 2012-01-07 14:28 +0100
Re: Lilupophilupop "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-07 16:13 +0100
Re: Lilupophilupop Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-01-07 18:03 +0100
Re: Lilupophilupop Gregor Kofler <usenet@gregorkofler.com> - 2012-01-07 20:34 +0100
Re: Lilupophilupop "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-08 14:53 +0100
Re: Lilupophilupop Gregor Kofler <usenet@gregorkofler.com> - 2012-01-08 15:27 +0100
Re: Lilupophilupop Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-08 10:00 -0500
Re: Lilupophilupop Gregor Kofler <usenet@gregorkofler.com> - 2012-01-08 18:29 +0100
Re: Lilupophilupop Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-08 15:49 -0500
Re: Lilupophilupop Gregor Kofler <usenet@gregorkofler.com> - 2012-01-08 22:59 +0100
Re: Lilupophilupop Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-08 17:38 -0500
| From | "M. Strobel" <sorry_no_mail_here@nowhere.dee> |
|---|---|
| Date | 2012-01-07 13:15 +0100 |
| Subject | Lilupophilupop |
| Message-ID | <9mqrbsFs13U1@mid.uni-berlin.de> |
Hi, there is currently a strong SQL injection attack going on, I find https://isc.sans.edu/diary.html?storyid=12127 very instructive. A page down it says "In this instance the PAGEID=189 parameter on page xxxxxxxx.asp is vulnerable". Now this should not happen. If you expect an integer, use your integer-read function! But it happens all the time. If you use tools/4GLs/CMSses you have to trust them, of course. /Str
[toc] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2012-01-07 08:15 -0500 |
| Message-ID | <je9ghb$bvv$1@dont-email.me> |
| In reply to | #4247 |
On 1/7/2012 7:15 AM, M. Strobel wrote: > Hi, > > there is currently a strong SQL injection attack going on, I find > https://isc.sans.edu/diary.html?storyid=12127 very instructive. > > A page down it says "In this instance the PAGEID=189 parameter on > page xxxxxxxx.asp is vulnerable". > > Now this should not happen. If you expect an integer, use your > integer-read function! > > But it happens all the time. If you use tools/4GLs/CMSses you > have to trust them, of course. > > /Str Validating all input from the user is just good programming practice. Nothing new here - it just shows there are a lot of programmers out there unconcerned with security. -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> |
|---|---|
| Date | 2012-01-07 18:27 +0100 |
| Message-ID | <je9v9o$hit$1@news.albasani.net> |
| In reply to | #4248 |
Jerry Stuckle schrieb: > Validating all input from the user is just good programming practice. And properly (!) escaping output (this includes stuff that goes into SQL queries). As I see it, these two simple measures should prevent 99% of all security vulnerabilities. I'd be interested in learning about the remaining 1% though. > Nothing new here - it just shows there are a lot of programmers out > there unconcerned with security. Indeed. But I don't understand why this is so. After all, we're not talking about the personal homepage of some newbie showing pictures of his dog and favourite cookie recipes. The problem exists also (if not especially) with real big professional sites, even sites where security is paramount (online banking), run by people who should have more than enough money to pay competent, security-aware programmers to do the job properly. I just don't get it. Of course, the worst about this new SQL injection attack is certainly that ridiculous name "Lilupophilupop". Greetings, Thomas -- Ce n'est pas parce qu'ils sont nombreux à avoir tort qu'ils ont raison! (Coluche)
[toc] | [prev] | [next] | [standalone]
| From | "J.O. Aho" <user@example.net> |
|---|---|
| Date | 2012-01-07 18:52 +0100 |
| Message-ID | <9mrf20Fm65U1@mid.individual.net> |
| In reply to | #4263 |
Thomas Mlynarczyk wrote: > Jerry Stuckle schrieb: >> Nothing new here - it just shows there are a lot of programmers out there >> unconcerned with security. > > Indeed. But I don't understand why this is so. After all, we're not talking > about the personal homepage of some newbie showing pictures of his dog and > favourite cookie recipes. The problem exists also (if not especially) with > real big professional sites, even sites where security is paramount (online > banking), run by people who should have more than enough money to pay > competent, security-aware programmers to do the job properly. I just don't get > it. The big issue is "maximize profit" and "finish on half the required time", when you have those two things as the main mantras, then everything will be crap, not just web sites and their security, but things like cell phones which won't hold more than max 3 years, crappy health care and insurances which don't cover anything at all. -- //Aho
[toc] | [prev] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2012-01-07 16:02 -0500 |
| Message-ID | <jeabsn$6m0$2@dont-email.me> |
| In reply to | #4264 |
On 1/7/2012 12:52 PM, J.O. Aho wrote: > Thomas Mlynarczyk wrote: >> Jerry Stuckle schrieb: > >>> Nothing new here - it just shows there are a lot of programmers out >>> there >>> unconcerned with security. >> >> Indeed. But I don't understand why this is so. After all, we're not >> talking >> about the personal homepage of some newbie showing pictures of his dog >> and >> favourite cookie recipes. The problem exists also (if not especially) >> with >> real big professional sites, even sites where security is paramount >> (online >> banking), run by people who should have more than enough money to pay >> competent, security-aware programmers to do the job properly. I just >> don't get >> it. > > The big issue is "maximize profit" and "finish on half the required > time", when you have those two things as the main mantras, then > everything will be crap, not just web sites and their security, but > things like cell phones which won't hold more than max 3 years, crappy > health care and insurances which don't cover anything at all. > > True to a big extent, J.O. But proper security practices are cheaper up front than trying to go back and fix the problem later. I think a much bigger problem here is there are a huge number of programmers who don't understand proper security practices. For instance, they think the only way someone can POST data to their site is from another page on their site, and validating data with javascript before it is sent is sufficient security. Nothing could be more wrong. -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | "Peter H. Coffin" <hellsop@ninehells.com> |
|---|---|
| Date | 2012-01-10 18:31 -0600 |
| Message-ID | <slrnjgpm3p.51n.hellsop@nibelheim.ninehells.com> |
| In reply to | #4263 |
On Sat, 07 Jan 2012 18:27:15 +0100, Thomas Mlynarczyk wrote:
> Jerry Stuckle schrieb:
>
>> Validating all input from the user is just good programming practice.
>
> And properly (!) escaping output (this includes stuff that goes into
> SQL queries). As I see it, these two simple measures should prevent
> 99% of all security vulnerabilities. I'd be interested in learning
> about the remaining 1% though.
>
>> Nothing new here - it just shows there are a lot of programmers out
>> there unconcerned with security.
>
> Indeed. But I don't understand why this is so. After all, we're not
> talking about the personal homepage of some newbie showing pictures
> of his dog and favourite cookie recipes. The problem exists also (if
> not especially) with real big professional sites, even sites where
> security is paramount (online banking), run by people who should have
> more than enough money to pay competent, security-aware programmers to
> do the job properly. I just don't get it.
Good programmers and idiots are indistinguishable to anyone that is not
a good programmer. The people making the hiring decisions are not good
programmers. Ergo, idiots and good programmers get hired in proportion
to the frequency of each in the job market, and the idiots move on to
other positions far more frequently, voluntarily or involuntarily.
Which also means that even if good programmers and idiots are in roughly
equal measure, the good programmers are not in the market for new jobs
nearly as often, make up a smaller portion of the market, and
not-programmers are unlikely to hire them by accident.
--
88. If a group of henchmen fail miserably at a task, I will not berate
them for incompetence then send the same group out to try the task
again.
--Peter Anspach's list of things to do as an Evil Overlord
[toc] | [prev] | [next] | [standalone]
| From | "M. Strobel" <sorry_no_mail_here@nowhere.dee> |
|---|---|
| Date | 2012-01-11 09:29 +0100 |
| Message-ID | <9n4vihFq54U1@mid.uni-berlin.de> |
| In reply to | #4411 |
Am 11.01.2012 01:31, schrieb Peter H. Coffin: > On Sat, 07 Jan 2012 18:27:15 +0100, Thomas Mlynarczyk wrote: > >> Jerry Stuckle schrieb: >> >>> Validating all input from the user is just good programming practice. >> >> And properly (!) escaping output (this includes stuff that goes into >> SQL queries). As I see it, these two simple measures should prevent >> 99% of all security vulnerabilities. I'd be interested in learning >> about the remaining 1% though. >> >>> Nothing new here - it just shows there are a lot of programmers out >>> there unconcerned with security. >> >> Indeed. But I don't understand why this is so. After all, we're not >> talking about the personal homepage of some newbie showing pictures >> of his dog and favourite cookie recipes. The problem exists also (if >> not especially) with real big professional sites, even sites where >> security is paramount (online banking), run by people who should have >> more than enough money to pay competent, security-aware programmers to >> do the job properly. I just don't get it. > > Good programmers and idiots are indistinguishable to anyone that is not > a good programmer. The people making the hiring decisions are not good > programmers. Ergo, idiots and good programmers get hired in proportion > to the frequency of each in the job market, and the idiots move on to > other positions far more frequently, voluntarily or involuntarily. > > Which also means that even if good programmers and idiots are in roughly > equal measure, the good programmers are not in the market for new jobs > nearly as often, make up a smaller portion of the market, and > not-programmers are unlikely to hire them by accident. > I agree. But beware the fallacy of the single cause. Good programmers and idiots can change under certain conditions - learn and un-learn good programming. And even good programmers make compromises in their code under the pressure of time-to-market. /Str.
[toc] | [prev] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2012-01-11 08:42 -0500 |
| Message-ID | <jek3l9$6p9$1@dont-email.me> |
| In reply to | #4412 |
On 1/11/2012 3:29 AM, M. Strobel wrote: > Am 11.01.2012 01:31, schrieb Peter H. Coffin: >> On Sat, 07 Jan 2012 18:27:15 +0100, Thomas Mlynarczyk wrote: >> >>> Jerry Stuckle schrieb: >>> >>>> Validating all input from the user is just good programming practice. >>> >>> And properly (!) escaping output (this includes stuff that goes into >>> SQL queries). As I see it, these two simple measures should prevent >>> 99% of all security vulnerabilities. I'd be interested in learning >>> about the remaining 1% though. >>> >>>> Nothing new here - it just shows there are a lot of programmers out >>>> there unconcerned with security. >>> >>> Indeed. But I don't understand why this is so. After all, we're not >>> talking about the personal homepage of some newbie showing pictures >>> of his dog and favourite cookie recipes. The problem exists also (if >>> not especially) with real big professional sites, even sites where >>> security is paramount (online banking), run by people who should have >>> more than enough money to pay competent, security-aware programmers to >>> do the job properly. I just don't get it. >> >> Good programmers and idiots are indistinguishable to anyone that is not >> a good programmer. The people making the hiring decisions are not good >> programmers. Ergo, idiots and good programmers get hired in proportion >> to the frequency of each in the job market, and the idiots move on to >> other positions far more frequently, voluntarily or involuntarily. >> >> Which also means that even if good programmers and idiots are in roughly >> equal measure, the good programmers are not in the market for new jobs >> nearly as often, make up a smaller portion of the market, and >> not-programmers are unlikely to hire them by accident. >> > > I agree. > > But beware the fallacy of the single cause. Good programmers and > idiots can change under certain conditions - learn and un-learn > good programming. > > And even good programmers make compromises in their code under > the pressure of time-to-market. > > /Str. Good programmers never need to make compromises which affect the quality of the code, no matter what the pressure. And the number of years one has been programming is not an indication of the quality of the programmer. -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | Erwin Moller <erwinmollerusenet@xs4all.nl> |
|---|---|
| Date | 2012-01-11 15:23 +0100 |
| Message-ID | <4f0d9b69$0$6966$e4fe514c@news2.news.xs4all.nl> |
| In reply to | #4412 |
On 1/11/2012 9:29 AM, M. Strobel wrote: > Am 11.01.2012 01:31, schrieb Peter H. Coffin: >> On Sat, 07 Jan 2012 18:27:15 +0100, Thomas Mlynarczyk wrote: >> >>> Jerry Stuckle schrieb: >>> >>>> Validating all input from the user is just good programming practice. >>> >>> And properly (!) escaping output (this includes stuff that goes into >>> SQL queries). As I see it, these two simple measures should prevent >>> 99% of all security vulnerabilities. I'd be interested in learning >>> about the remaining 1% though. >>> >>>> Nothing new here - it just shows there are a lot of programmers out >>>> there unconcerned with security. >>> >>> Indeed. But I don't understand why this is so. After all, we're not >>> talking about the personal homepage of some newbie showing pictures >>> of his dog and favourite cookie recipes. The problem exists also (if >>> not especially) with real big professional sites, even sites where >>> security is paramount (online banking), run by people who should have >>> more than enough money to pay competent, security-aware programmers to >>> do the job properly. I just don't get it. >> >> Good programmers and idiots are indistinguishable to anyone that is not >> a good programmer. The people making the hiring decisions are not good >> programmers. Ergo, idiots and good programmers get hired in proportion >> to the frequency of each in the job market, and the idiots move on to >> other positions far more frequently, voluntarily or involuntarily. >> >> Which also means that even if good programmers and idiots are in roughly >> equal measure, the good programmers are not in the market for new jobs >> nearly as often, make up a smaller portion of the market, and >> not-programmers are unlikely to hire them by accident. >> > > I agree. > > But beware the fallacy of the single cause. Good programmers and > idiots can change under certain conditions - learn and un-learn > good programming. my 2 cent: I seldom saw good programmers go downhill and become bad. But a lot of bad programmers will never become good, because they lack analytical skills. I do not know if it is nature or nurture (probably both), but many people simply lack analytical skills. > > And even good programmers make compromises in their code under > the pressure of time-to-market. Yes, but good programmers complain clearly to the client/boss when they are expected to deliver something complex in a short time. Take some pride in your work! I flat out refuse when I expect my work will suck. I do not mind some healthy pressure, but when I am expected to take all kinds of strange/stupid shortcuts, I simply refuse. Unless you do drone-work, you must have some time to think and reflect on the code you produce. Regards, Erwin Moller -- "That which can be asserted without evidence, can be dismissed without evidence." -- Christopher Hitchens
[toc] | [prev] | [next] | [standalone]
| From | Gregor Kofler <usenet@gregorkofler.com> |
|---|---|
| Date | 2012-01-07 14:28 +0100 |
| Message-ID | <je9h9g$f7n$1@dont-email.me> |
| In reply to | #4247 |
Am 2012-01-07 13:15, M. Strobel meinte: > Hi, > > there is currently a strong SQL injection attack going on, I find > https://isc.sans.edu/diary.html?storyid=12127 very instructive. > > A page down it says "In this instance the PAGEID=189 parameter on > page xxxxxxxx.asp is vulnerable". > > Now this should not happen. If you expect an integer, use your > integer-read function! And? This should be common practice for any web application developer. Nothing new here. > But it happens all the time. If you use tools/4GLs/CMSses you > have to trust them, of course. How can I "trust" (or "mistrust") 4GLs? And no - I don't have to and don't trust stock CMS' when it comes to security issues. Particularly with their plethora of plugins. Gregor -- http://vxweb.net
[toc] | [prev] | [next] | [standalone]
| From | "M. Strobel" <sorry_no_mail_here@nowhere.dee> |
|---|---|
| Date | 2012-01-07 16:13 +0100 |
| Message-ID | <9mr5p2Fbh8U2@mid.uni-berlin.de> |
| In reply to | #4249 |
Am 07.01.2012 14:28, schrieb Gregor Kofler: > Am 2012-01-07 13:15, M. Strobel meinte: >> But it happens all the time. If you use tools/4GLs/CMSses you >> have to trust them, of course. > > How can I "trust" (or "mistrust") 4GLs? And no - I don't have to and > don't trust stock CMS' when it comes to security issues. Particularly > with their plethora of plugins. > > Gregor > > You saw the _if_ in front of _you use_, did you? /Str
[toc] | [prev] | [next] | [standalone]
| From | Thomas 'PointedEars' Lahn <PointedEars@web.de> |
|---|---|
| Date | 2012-01-07 18:03 +0100 |
| Message-ID | <5849546.bgypaU67uL@PointedEars.de> |
| In reply to | #4257 |
M. Strobel wrote: > Am 07.01.2012 14:28, schrieb Gregor Kofler: >> Am 2012-01-07 13:15, M. Strobel meinte: >>> But it happens all the time. If you use tools/4GLs/CMSses you >>> have to trust them, of course. >> >> How can I "trust" (or "mistrust") 4GLs? And no - I don't have to and >> don't trust stock CMS' when it comes to security issues. Particularly >> with their plethora of plugins. > > You saw the _if_ in front of _you use_, did you? Probably yes. But that does not make your statement a sound argument. Even if you use software, you do _not_ *have* to trust it. In fact, healthy scepticism towards software is always indicated, because software is written by humans, and humans do make mistakes. PointedEars -- Danny Goodman's books are out of date and teach practices that are positively harmful for cross-browser scripting. -- Richard Cornford, cljs, <cife6q$253$1$8300dec7@news.demon.co.uk> (2004)
[toc] | [prev] | [next] | [standalone]
| From | Gregor Kofler <usenet@gregorkofler.com> |
|---|---|
| Date | 2012-01-07 20:34 +0100 |
| Message-ID | <jea6ni$7g9$1@dont-email.me> |
| In reply to | #4257 |
Am 2012-01-07 16:13, M. Strobel meinte: > Am 07.01.2012 14:28, schrieb Gregor Kofler: >> Am 2012-01-07 13:15, M. Strobel meinte: > >>> But it happens all the time. If you use tools/4GLs/CMSses you >>> have to trust them, of course. >> >> How can I "trust" (or "mistrust") 4GLs? And no - I don't have to and >> don't trust stock CMS' when it comes to security issues. Particularly >> with their plethora of plugins. >> >> Gregor >> >> > You saw the _if_ in front of _you use_, did you? Yes. As Thomas said - you don't *have* *to* trust it (though it's handy to have someone else to blame, when problems arise). Gregor
[toc] | [prev] | [next] | [standalone]
| From | "M. Strobel" <sorry_no_mail_here@nowhere.dee> |
|---|---|
| Date | 2012-01-08 14:53 +0100 |
| Message-ID | <9mtldvFe7jU1@mid.uni-berlin.de> |
| In reply to | #4266 |
Am 07.01.2012 20:34, schrieb Gregor Kofler: > Am 2012-01-07 16:13, M. Strobel meinte: >> Am 07.01.2012 14:28, schrieb Gregor Kofler: >>> Am 2012-01-07 13:15, M. Strobel meinte: >> >>>> But it happens all the time. If you use tools/4GLs/CMSses you >>>> have to trust them, of course. >>> >>> How can I "trust" (or "mistrust") 4GLs? Believe that the software does what it is meant to. Are you going to ask what I think it is meant to, or what I thing you think it is meant to? >>> And no - I don't have to and >>> don't trust stock CMS' when it comes to security issues. Particularly >>> with their plethora of plugins. >>> >>> Gregor >>> >>> >> You saw the _if_ in front of _you use_, did you? > > Yes. As Thomas said - you don't *have* *to* trust it (though it's handy > to have someone else to blame, when problems arise). > > Gregor > and to Thomas PE I think using a software like Coldfusion shows that you trust it - at least so far as to say it is usable. Sure there is room to debate "trust". /Str.
[toc] | [prev] | [next] | [standalone]
| From | Gregor Kofler <usenet@gregorkofler.com> |
|---|---|
| Date | 2012-01-08 15:27 +0100 |
| Message-ID | <jec94t$3at$1@dont-email.me> |
| In reply to | #4284 |
Am 2012-01-08 14:53, M. Strobel meinte: > Am 07.01.2012 20:34, schrieb Gregor Kofler: >> Am 2012-01-07 16:13, M. Strobel meinte: >>> Am 07.01.2012 14:28, schrieb Gregor Kofler: >>>> Am 2012-01-07 13:15, M. Strobel meinte: >>> >>>>> But it happens all the time. If you use tools/4GLs/CMSses you >>>>> have to trust them, of course. >>>> >>>> How can I "trust" (or "mistrust") 4GLs? > > Believe that the software does what it is meant to. > Are you going to ask what I think it is meant to, or what I thing > you think it is meant to? A 4th generation language can have bugs and allow exploits, just like 3rd generation languages. Despite the version upgrade, you still have to write scripts or programs (and care about security issues, which arise in the scope of your script). A CMS is a ready-to-use product, that *should* take care of such issues and rule out any security issues in the scope of the scripts of the application. >> Gregor >> > and to Thomas PE > > I think using a software like Coldfusion shows that you trust it > - at least so far as to say it is usable. CF is a PITA, but, yes, it's "usable" (some - or rather few - people even *like* CF). I've never used the term "trust" with a language - they are "flexible", "concise", "comfortable", etc. I don't know what a "trustworthy" language is. Besides, I don't know why CF is considered a 4GL (according to WikiPedia) and PHP is not. > Sure there is room to debate "trust". Sounds like a discussion for discussions sake. Gregor
[toc] | [prev] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2012-01-08 10:00 -0500 |
| Message-ID | <jecb2i$dti$1@dont-email.me> |
| In reply to | #4291 |
On 1/8/2012 9:27 AM, Gregor Kofler wrote: > Am 2012-01-08 14:53, M. Strobel meinte: >> Am 07.01.2012 20:34, schrieb Gregor Kofler: >>> Am 2012-01-07 16:13, M. Strobel meinte: >>>> Am 07.01.2012 14:28, schrieb Gregor Kofler: >>>>> Am 2012-01-07 13:15, M. Strobel meinte: >>>> >>>>>> But it happens all the time. If you use tools/4GLs/CMSses you >>>>>> have to trust them, of course. >>>>> >>>>> How can I "trust" (or "mistrust") 4GLs? >> >> Believe that the software does what it is meant to. >> Are you going to ask what I think it is meant to, or what I thing >> you think it is meant to? > > A 4th generation language can have bugs and allow exploits, just like > 3rd generation languages. Despite the version upgrade, you still have to > write scripts or programs (and care about security issues, which arise > in the scope of your script). A CMS is a ready-to-use product, that > *should* take care of such issues and rule out any security issues in > the scope of the scripts of the application. > Your reasoning is faulty. A 4GL should rule out security issues in the scope of the language. A CMS can also have bugs and allow exploits. And even with a CMS you have to write your own scripts. Also, CMS's have had any number of security problems over the years, even within their own scope. >>> Gregor >>> >> and to Thomas PE >> >> I think using a software like Coldfusion shows that you trust it >> - at least so far as to say it is usable. > > CF is a PITA, but, yes, it's "usable" (some - or rather few - people > even *like* CF). I've never used the term "trust" with a language - they > are "flexible", "concise", "comfortable", etc. I don't know what a > "trustworthy" language is. > Besides, I don't know why CF is considered a 4GL (according to > WikiPedia) and PHP is not. > >> Sure there is room to debate "trust". > > Sounds like a discussion for discussions sake. > > Gregor I trust languages (even 4GL) much more than I do CMS's. -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | Gregor Kofler <usenet@gregorkofler.com> |
|---|---|
| Date | 2012-01-08 18:29 +0100 |
| Message-ID | <jecjp4$21e$1@dont-email.me> |
| In reply to | #4293 |
Am 2012-01-08 16:00, Jerry Stuckle meinte: > On 1/8/2012 9:27 AM, Gregor Kofler wrote: >> Am 2012-01-08 14:53, M. Strobel meinte: >>> Am 07.01.2012 20:34, schrieb Gregor Kofler: >>>> Am 2012-01-07 16:13, M. Strobel meinte: >>>>> Am 07.01.2012 14:28, schrieb Gregor Kofler: >>>>>> Am 2012-01-07 13:15, M. Strobel meinte: >>>>> >>>>>>> But it happens all the time. If you use tools/4GLs/CMSses you >>>>>>> have to trust them, of course. >>>>>> >>>>>> How can I "trust" (or "mistrust") 4GLs? >>> >>> Believe that the software does what it is meant to. >>> Are you going to ask what I think it is meant to, or what I thing >>> you think it is meant to? >> >> A 4th generation language can have bugs and allow exploits, just like >> 3rd generation languages. Despite the version upgrade, you still have to >> write scripts or programs (and care about security issues, which arise >> in the scope of your script). A CMS is a ready-to-use product, that >> *should* take care of such issues and rule out any security issues in >> the scope of the scripts of the application. >> > > Your reasoning is faulty. A 4GL should rule out security issues in the > scope of the language. A CMS can also have bugs and allow exploits. I can't see any difference to 3GLs. Take the mentioned CF. It allows to define the data type of supplied arguments for function calls. It allows intrinsic escaping of query strings. Both features *can* (and should) be used, but it's not obligatory (and they are not "enabled" by some default setting). Not doing can and will lead to injections. It's more or less the same thing as with PHP. > And even with a CMS you have to write your own scripts. Pardon? You can, but you don't have to. No need to write scripts with WordPress, Joomla!, Typo3, ... > Also, CMS's have had any number of security problems over the years, > even within their own scope. Agreed. PHP-Nuke comes to my mind... > I trust languages (even 4GL) much more than I do CMS's. So do I. Gregor
[toc] | [prev] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2012-01-08 15:49 -0500 |
| Message-ID | <jecvg6$e2h$1@dont-email.me> |
| In reply to | #4301 |
On 1/8/2012 12:29 PM, Gregor Kofler wrote: > Am 2012-01-08 16:00, Jerry Stuckle meinte: >> On 1/8/2012 9:27 AM, Gregor Kofler wrote: >>> Am 2012-01-08 14:53, M. Strobel meinte: >>>> Am 07.01.2012 20:34, schrieb Gregor Kofler: >>>>> Am 2012-01-07 16:13, M. Strobel meinte: >>>>>> Am 07.01.2012 14:28, schrieb Gregor Kofler: >>>>>>> Am 2012-01-07 13:15, M. Strobel meinte: >>>>>> >>>>>>>> But it happens all the time. If you use tools/4GLs/CMSses you >>>>>>>> have to trust them, of course. >>>>>>> >>>>>>> How can I "trust" (or "mistrust") 4GLs? >>>> >>>> Believe that the software does what it is meant to. >>>> Are you going to ask what I think it is meant to, or what I thing >>>> you think it is meant to? >>> >>> A 4th generation language can have bugs and allow exploits, just like >>> 3rd generation languages. Despite the version upgrade, you still have to >>> write scripts or programs (and care about security issues, which arise >>> in the scope of your script). A CMS is a ready-to-use product, that >>> *should* take care of such issues and rule out any security issues in >>> the scope of the scripts of the application. >>> >> >> Your reasoning is faulty. A 4GL should rule out security issues in the >> scope of the language. A CMS can also have bugs and allow exploits. > > I can't see any difference to 3GLs. Take the mentioned CF. It allows to > define the data type of supplied arguments for function calls. It allows > intrinsic escaping of query strings. Both features *can* (and should) be > used, but it's not obligatory (and they are not "enabled" by some > default setting). Not doing can and will lead to injections. It's more > or less the same thing as with PHP. > First of all, please study up on what a 3GL language is and what a 4GL language is (I won't get into it here - it's off topic in this newsgroup). >> And even with a CMS you have to write your own scripts. > > Pardon? You can, but you don't have to. No need to write scripts with > WordPress, Joomla!, Typo3, ... > I've used WordPress, Joomla and Drupal. In every one of them I've ended up writing code for my client because the plugins don't do what he wants. Of course, if you just tell the client he can only do what the addons allow, that's one thing. I prefer to satisfy the client's needs. >> Also, CMS's have had any number of security problems over the years, >> even within their own scope. > > Agreed. PHP-Nuke comes to my mind... > And WordPress and Joomla and Drupal and all kinds of others. >> I trust languages (even 4GL) much more than I do CMS's. > > So do I. > > Gregor > > -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | Gregor Kofler <usenet@gregorkofler.com> |
|---|---|
| Date | 2012-01-08 22:59 +0100 |
| Message-ID | <jed3kq$8aj$1@dont-email.me> |
| In reply to | #4318 |
Am 2012-01-08 21:49, Jerry Stuckle meinte: >> I can't see any difference to 3GLs. Take the mentioned CF. It allows to >> define the data type of supplied arguments for function calls. It allows >> intrinsic escaping of query strings. Both features *can* (and should) be >> used, but it's not obligatory (and they are not "enabled" by some >> default setting). Not doing can and will lead to injections. It's more >> or less the same thing as with PHP. >> > > First of all, please study up on what a 3GL language is and what a 4GL > language is (I won't get into it here - it's off topic in this newsgroup). LOL. Yes, I can ready the Wikipedia article. From the list there, I know and have worked with Clipper, ColdFusion and Mathematica. (And ColdFusion in particular urges for a comparison to PHP.) BTW: the *German* Wikipedia article states that "The term 4GL cannot be exactly defined and is used mainly for marketing purposes". >>> And even with a CMS you have to write your own scripts. >> >> Pardon? You can, but you don't have to. No need to write scripts with >> WordPress, Joomla!, Typo3, ... > I've used WordPress, Joomla and Drupal. In every one of them I've ended > up writing code for my client because the plugins don't do what he wants. So? As I said: you can, but you don't have to. And even then, one (well, perhaps not you) would use the CMS' own functions, classes and framework. Besides, I'm pretty sure the *vast* majority of CMS based websites out there don't sport any individual code snippets. > Of course, if you just tell the client he can only do what the addons > allow, that's one thing. I prefer to satisfy the client's needs. You are every PHP developer's hero. I'd have never thought of that... Gregor
[toc] | [prev] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2012-01-08 17:38 -0500 |
| Message-ID | <jed5ts$krt$1@dont-email.me> |
| In reply to | #4321 |
On 1/8/2012 4:59 PM, Gregor Kofler wrote: > Am 2012-01-08 21:49, Jerry Stuckle meinte: > >>> I can't see any difference to 3GLs. Take the mentioned CF. It allows to >>> define the data type of supplied arguments for function calls. It allows >>> intrinsic escaping of query strings. Both features *can* (and should) be >>> used, but it's not obligatory (and they are not "enabled" by some >>> default setting). Not doing can and will lead to injections. It's more >>> or less the same thing as with PHP. >>> >> >> First of all, please study up on what a 3GL language is and what a 4GL >> language is (I won't get into it here - it's off topic in this newsgroup). > > LOL. Yes, I can ready the Wikipedia article. From the list there, I know > and have worked with Clipper, ColdFusion and Mathematica. (And > ColdFusion in particular urges for a comparison to PHP.) > > BTW: the *German* Wikipedia article states that > "The term 4GL cannot be exactly defined and is used mainly for marketing > purposes". > >>>> And even with a CMS you have to write your own scripts. >>> >>> Pardon? You can, but you don't have to. No need to write scripts with >>> WordPress, Joomla!, Typo3, ... > >> I've used WordPress, Joomla and Drupal. In every one of them I've ended >> up writing code for my client because the plugins don't do what he wants. > > So? As I said: you can, but you don't have to. And even then, one (well, > perhaps not you) would use the CMS' own functions, classes and > framework. Besides, I'm pretty sure the *vast* majority of CMS based > websites out there don't sport any individual code snippets. > But even if you're using the CMS's own functions, classes and frameworks you can have security problems in your own code. And yes, I'm sure there are sites which don't use anything else. Just as there are sites which use no server-side programming at all. I'd like to see where you get your statistics that the "*vast majority of CMS based websites out there don't support any individual code snippets". >> Of course, if you just tell the client he can only do what the addons >> allow, that's one thing. I prefer to satisfy the client's needs. > > You are every PHP developer's hero. I'd have never thought of that... > > Gregor -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [standalone]
Back to top | Article view | comp.lang.php
csiph-web