Re: PHP class files without <?php at the top

From: Date: Mon, 09 Apr 2012 20:28:11 +0000
Subject: Re: PHP class files without <?php at the top
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14  Groups: php.internals 
Request: Send a blank email to [email protected] to get a copy of this message
Hi,

2012/4/10 Ángel González <[email protected]>:
> On 09/04/12 21:17, Yasuo Ohgaki wrote:
>> Please do not tell me that programmer should
>> learn not to, since it's  not a protection but education.
> Hire a more competent programmer? If he writes such code,
> he will be completely unaware of the subtleties of XSS, or how
> SQL should be escaped, and his code is probably beyond
> "protection". You're better served by rewriting it.

I'm teaching at University on occasion.
Do you forget how you have learned languages?

>
>
>> If programmers/administrators could disable embed mode,
>> then systems will be protected from vulnerable codes.
> How do you enforce that the application you need doesn't rely on it?
>
> Note: 'education' is also forbidden as you restricted it in the
> previous question. :-)
>

Why do you insist while there is a systematic solution for it?

Regards,

--
Yasuo Ohgaki


Thread (70 messages)

« previous php.internals (#59545) next »