![]() |
|
What makes PHP so secure? - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Coding (https://sinister.li/Forum-Coding) +--- Forum: PHP (https://sinister.li/Forum-PHP) +--- Thread: What makes PHP so secure? (/Thread-What-makes-PHP-so-secure) Pages:
1
2
|
RE: What makes PHP so secure? - Rou - 01-22-2016 (01-21-2016, 09:16 PM)Cosvo Wrote: Hello sinisterly. Because no one else seems to be willing to give you a proper answer, allow me. PHP is secure in the sense that it doesn't (in theory) allow you to do unsafe memory operations that can make your application vulnerable or crash, but this isn't unique to PHP. PHP isn't any more secure than other popular languages like Python, Javascript, Java or C. PHP is not secure in the sense that it's unhackable. That's a ridiculous claim which is easily proven false. Using PHP doesn't give your application any safety from hackers, researchers, crackers or pirates what-so-ever. As a matter of fact, if you choose PHP, odds are that you'll write an easily hackable application, because PHP coders tend to be Bad Programmers™. When coding in PHP, you also need to leave your source code open for anyone to see, which makes it easier to analyse and find exploits. You can obfuscate, but decent PHP obfuscators are far and few between (No, eval(gzuncompress(base64_decode())) is NOT decent obfuscation!) As for PHP-rats not needing VPNs, that's just plain wrong. A VPN isn't needed for any RATs, PHP or not. What you might need is a proxy, but even that is rare. What PHP offers you is the ability to create HTTP requests with ease, and it gives you access to sockets with fsockopen, but you can replicate this in any language if you're skilled enough. I'd also like to recommend that you do not create RATs in PHP, simply because PHP doesn't have access to low-level system calls. The best you have in PHP is exec(), unless you write your own modules. Hope this cleared things up a little bit. TL;DR: PHP is "secure" because it doesn't allow you to fuck around with memory. PHP code is often easily hackable because PHP coders tend to suck. PHP applications are not secure just because they're written in PHP. RE: What makes PHP so secure? - Inori - 01-22-2016 (01-22-2016, 10:59 AM)Rou Wrote: TL;DR: This is exactly correct. The memory fuckage is a big reason why server apps crash, but other than that, the security of the system is up to the programmer, just like everything else. I forget where, but I remember reading that PHP has piss-all for built-in security, so it's really all up to the dev to not use shitty code. RE: What makes PHP so secure? - The Real Slim Shady - 01-22-2016 (01-22-2016, 10:59 AM)Rou Wrote: PHP is "secure" because it doesn't allow you to fuck around with memory. (01-22-2016, 01:57 PM)Chitoge Wrote: This is exactly correct. The memory fuckage is a big reason why server apps crash, but other than that, the security of the system is up to the programmer, just like everything else. I've seen shitty PHP code take down a server with 16 cores and 32GB ram if i recall correctly. Either way it was by far one of the beastiest machines i've ever touched. but it was a logic error in a loop that would run to its maximum execution time every time the script was hit. which i believe was configured to 2 minutes for some reason. so this never ending loop would run for 2 minutes putting shit in memory every time someone accessed it. and some spam bots started targetting the page because there was a web form on it. even though they couldn't actually submit anything, the fact that the page loaded was enough. So ya - you don't need direct write access to the stack to cause issues with memory in PHP RE: What makes PHP so secure? - Rou - 01-22-2016 (01-22-2016, 02:18 PM)The Real Slim Shady Wrote: I've seen shitty PHP code take down a server with 16 cores and 32GB ram if i recall correctly. Either way it was by far one of the beastiest machines i've ever touched. but it was a logic error in a loop that would run to its maximum execution time every time the script was hit. which i believe was configured to 2 minutes for some reason. so this never ending loop would run for 2 minutes putting shit in memory every time someone accessed it. and some spam bots started targetting the page because there was a web form on it. even though they couldn't actually submit anything, the fact that the page loaded was enough. Memory depletion and infinite loops are different issues from memory corruption and access violations, though. RE: What makes PHP so secure? - ImmNinjaxD - 01-22-2016 (01-22-2016, 10:59 AM)Rou Wrote: Because no one else seems to be willing to give you a proper answer, allow me. As i'm not much of a programmer, I was actually pretty interested in the answer. Sue me Thanks for a valid response! RE: What makes PHP so secure? - Sans - 01-27-2016 I like how no one answered his real question because he's too dumb to know how to ask it. Here, kid: the reason a "PHP RAT" won't expose your IP is because the client is connecting back to a Web server, not a tool running on your PC. It's not even really a "PHP RAT" by the way, it's just a set of scripts written to respond to HTTP requests from the infected machine. RE: What makes PHP so secure? - Skullmeat - 01-27-2016 This thread has gone far enough, and is not longer productive. Locked. |