Posted by Michael Fesser on 01/03/08 17:37
..oO(Jerry Stuckle)
>I understand. And with appropriate configuration, PHP is quite secure.
>
>But some people don't know how to configure it properly.
>
>And a disabled safe_mode would be reason for _me_ to change hosts.
>Someone so lax on security shouldn't be in business.
safe_mode will be removed in PHP 6:
| As safe_mode is a name that gives the wrong signals as making PHP
| safe, we all agreed that we should remove this function. It can never
| be made totally safe as there will always be ways to circumvent
| safe_mode through libraries. This kind of functionality also better
| belongs in the web server or other security scheme.
Micha
Navigation:
[Reply to this message]
|