|
|
|
![]() |
|
|||||||
|
||||||||
![]() |
|
|
Thread Tools | Rate Thread | Display Modes |
|
|
|
#1
|
|||||
|
|||||
|
PHP as a security risk
Im in the process of re-designing my school districts webpage. I am the webmaster for the school district and we have discussed changing to php. Our web host (who also host our robotics website) says that it is a security risk and doesnt know if he'll allow it. Can someone inform me on what he is talking about?
Brandon what are your feelings you seem to have a lot of experience with this? www.udsd.k12.pa.us thats the site now... http://ud.akwire.net is what we're workin on at this time. thank you in advance |
|
#2
|
|||
|
|||
|
May I ask what web server and OS is being run?
|
|
#3
|
|||||
|
|||||
|
Re: PHP as a security risk
Quote:
They mention: A completely secure system is a virtual impossibility, so an approach often used in the security profession is one of balancing risk and usability. No matter what OS and/or configuration you are running, as long as you keep up to date with security patches & new releases, you should be fine. We use linux+php at work and deal with alot of highly sensitive data. If you configure it correctly and know how to manitain it, there shouldn't be any security problems running php. |
|
#4
|
||||
|
||||
|
If properly implemented and kept up to date, the security risks are minimal. Many large scale websites use PHP and do not have any problems.
|
|
#5
|
|||||
|
|||||
|
hah..thank you brandon....i told them this and they said its a security risk blah blah blah...and i knew right where to come for proof...booh yaah
|
|
#6
|
|||||
|
|||||
|
Show them this:
http://news.com.com/2100-1023-963937.html?tag=lh and ask them if a large company such as Yahoo would drop their own 100% custom scripting language to use something that is insecure.. |
|
#7
|
|||||
|
|||||
|
thank you...i just sent him an email containg the information and the links that you gave me.
Brandon would you mind, if he needs to talk to someone that has experience running a php server, if i put him in contact with you? |
|
#8
|
|||||
|
|||||
|
Quote:
![]() |
|
#9
|
||||
|
||||
|
Quote:
|
|
#10
|
||||||
|
||||||
|
Does this webhost allow other scripting languages, perl, asp, etc?
Any scripting language can be used to create insecure scripts that can be exploited. This is the nature of (any) language. If they don't allow any scripting languages for security reasons, they shouldn't allow php either. However, I have no reason to beleive that PHP is less secure by default then other languages (if not more secure). |
![]() |
| Thread Tools | |
| Display Modes | Rate This Thread |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Learning PHP | Leon Machado IV | Website Design/Showcase | 15 | 20-08-2003 08:03 |
| FREE web design, php, and 3ds max classes | Jeremy_Mc | General Forum | 0 | 31-01-2003 15:42 |
| php vs. perl | Jack | Website Design/Showcase | 20 | 29-12-2002 17:01 |
| What's better, PERL/cgi or PHP/my_sql? | mikefrei | Programming | 10 | 27-05-2002 22:50 |
| NASA security problem. | Anthony S. | General Forum | 8 | 03-01-2002 11:33 |