Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: Security Hardening . . . . . . . (was Re: [tlug] Host Blocking and Logfile Parsing)
- Date: Sun, 21 Jan 2007 12:34:46 +0900 (JST)
- From: Curt Sampson <cjs@example.com>
- Subject: Re: Security Hardening . . . . . . . (was Re: [tlug] Host Blocking and Logfile Parsing)
- References: <Pine.NEB.4.64.0701201053020.1314@example.com> <1169300108.24083.7.camel@example.com> <Pine.NEB.4.64.0701211038210.1314@example.com> <20070120220108.6538fc7c.jep200404@example.com>
On Sat, 20 Jan 2007, Jim wrote:
Learn how to write safe shell scripts. ... As with shell scripts, learn how to write safe PHP code.
This is a terrible approach to security. Rather than asking people to be perfect, it's better to assume that people will err, and create systems that either make particular errors impossible, or catch them and deal with them safely when the occur.
Sandboxing is good, but sophisticated web apps need to interact enough with the rest of the system that big holes in sandboxing would be needed.
Not in my experience. Most of the web applications I've seen need only to load their code, read data files and talk to a database.
Perhaps you could give me some examples of the "big hols in sandboxing" you feel would be necessary.
cjs -- Curt Sampson <cjs@example.com> +81 90 7737 2974
- References:
- [tlug] Host Blocking and Logfile Parsing
- From: Curt Sampson
- Re: [tlug] Host Blocking and Logfile Parsing
- From: scott
- Re: [tlug] Host Blocking and Logfile Parsing
- From: Curt Sampson
- Security Hardening . . . . . . . (was Re: [tlug] Host Blocking and Logfile Parsing)
- From: Jim
Home | Main Index | Thread Index
- Prev by Date: Security Hardening . . . . . . . (was Re: [tlug] Host Blocking and Logfile Parsing)
- Next by Date: [tlug] TLUG site is becomming a spammers delight!
- Previous by thread: Security Hardening . . . . . . . (was Re: [tlug] Host Blocking and Logfile Parsing)
- Next by thread: Security Hardening . . . . . . . (was Re: [tlug] Host Blocking and Logfile Parsing)
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links