Posted by John Nichel on 11/15/05 18:38
Leonard Burton wrote:
> HI All,
>
>
>>Every server I work on is set to not allow short tags, and I work on
>>about 7 different state, federal, and commercial ones.
>
>
> Why turn off short tags? Does that make things more secure?
Don't know if it makes it any more or less secure. I turn them off
because I don't use them (I also disable quite a few functions that we
don't use). Idea being that if it's not needed, don't make it available
to be exploited (if an exploit exists now or in the future).
--
John C. Nichel IV
Programmer/System Admin (ÜberGeek)
Dot Com Holdings of Buffalo
716.856.9675
jnichel@dotcomholdingsofbuffalo.com
[Back to original message]
|