<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>Random Hacks: Yet Another PHP Security Hole</title>
    <link>http://www.randomhacks.net/articles/2002/07/22/yet-another-php-hole</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description>Technology and Other Fun Stuff</description>
    <item>
      <title>Yet Another PHP Security Hole</title>
      <description>    &lt;p&gt;&lt;a href='http://news.com.com/2100-1001-945480.html'&gt;A new security
    problem&lt;/a&gt; has been discovered in PHP 4.2.x.  This is not the &lt;a href='http://news.com.com/2100-1001-847092.html'&gt;first&lt;/a&gt; major hole
    in PHP, and it probably won't be the last.&lt;/p&gt;

    &lt;p&gt;Even if your PHP runtime is secure, it's &lt;a href='http://old.lwn.net/2001/0704/a/study-in-scarlet.php3'&gt;really
    hard&lt;/a&gt; to write secure PHP scripts.  There's so many things that can
    go wrong--malicious users setting "internal" global variables, &lt;a href='http://www.phpadvisory.com/advisories/view.phtml?ID=7'&gt;SQL
    injection&lt;/a&gt; attacks, ".inc" files containing passwords, and a whole
    host of other all-to-common bugs.&lt;/p&gt;

    &lt;p&gt;Just say no.&lt;/p&gt;</description>
      <pubDate>Mon, 22 Jul 2002 00:00:00 -0400</pubDate>
      <guid isPermaLink="false">urn:uuid:08169500-de0a-445f-9d5d-4e24aa591107</guid>
      <author>Eric</author>
      <link>http://www.randomhacks.net/articles/2002/07/22/yet-another-php-hole</link>
      <category>Security</category>
      <trackback:ping>http://www.randomhacks.net/articles/trackback/14</trackback:ping>
    </item>
  </channel>
</rss>
