Re: PHP security (or the lack thereof)

2006-06-26 Thread Tobias J. Kreidl
On Fri, 23 Jun 2006, Crispin Cowan wrote: > [EMAIL PROTECTED] wrote: > > Trying to make the language 'safe' won't fix it because the language > > is not the problem. The real problem is the way PHP is presented to > > most new developers. > > > > * snip * > > > That is a fascinating perspective.

Re: Solaris /usr/bin/mailx exploit (SPARC)

2001-05-16 Thread Tobias J. Kreidl
Andrew Hilborne <[EMAIL PROTECTED]> wrote on Tue, 15 May 2001 14:15:45 +0100: > Just how do you force 0600 on mailboxes which don't exist (many MUAs > remove empty mailboxes?) > > Since you cannot easily do this, at the very least a malicious user > should be able to steal other users' mail. I th