<?xml version="1.0" encoding="utf-8" ?><rss version="2.0" xml:base="https://www.webmaster-forums.net/crss/node/1037610" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title></title>
    <link>https://www.webmaster-forums.net/crss/node/1037610</link>
    <description></description>
    <language>en</language>
          <item>
    <title></title>
    <link>https://www.webmaster-forums.net/webmasters-corner/march-php-month-bugs-back-your-sites#comment-1215917</link>
    <description> &lt;p&gt;Agreed with everything Abhi said. This person is only doing what he&#039;s doing after many months (if not years) of frustration at the PHP Security Team. Note one of the quotes:&lt;/p&gt;
&lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;p&gt;Quote: As a vulnerability reporter you feel kinda puzzled how people among the PHP Security Response Team can claim in public that they do not know about any security vulnerability in PHP, when you disclosed about 20 holes to them in the two weeks before.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;He&#039;s given them plenty of warning. They&#039;ve had many opportunities to fix the problems, but they&#039;ve continually ignored them or told people they don&#039;t exist. I&#039;ve heard of Microsoft taking a similar tack when it comes to bugs, it&#039;s not acceptable from them so it&#039;s definitely no acceptable in a FLOSS project!&lt;/p&gt;
&lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;p&gt;&lt;strong&gt;Abhi wrote:&lt;/strong&gt; Anyway, I&#039;m glad this is finally happening. In my opinion, PHP has been resting on its laurels somewhat in the last couple of years -- not just in security. I hope the Month of Bugs will either drive the project to refocus, or drive its users to better technologies.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Now all we need is a &#039;PHP Month of namespaces&#039; or some of the other things on &lt;a href=&quot;http://www.webmaster-forums.net/showthread.php?t=36590#post210655&quot; class=&quot;bb-url&quot;&gt;Abhi&#039;s list of reasons&lt;/a&gt; why PHP sucks (my favourite TWF post ever). &lt;img src=&quot;https://www.webmaster-forums.net/misc/smileys/smile.png&quot; title=&quot;Smiling&quot; alt=&quot;Smiling&quot; class=&quot;smiley-content&quot; /&gt;&lt;/p&gt;
 </description>
     <pubDate>Wed, 28 Feb 2007 01:44:16 +0000</pubDate>
 <dc:creator>JeevesBond</dc:creator>
 <guid isPermaLink="false">comment 1215917 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/webmasters-corner/march-php-month-bugs-back-your-sites#comment-1215748</link>
    <description> &lt;p&gt;Ahhh... that kinda clarifies it for me. I figured he was doing this without giving them a good chance to fix PHP in advance.&lt;/p&gt;
 </description>
     <pubDate>Sun, 25 Feb 2007 10:00:01 +0000</pubDate>
 <dc:creator>andy206uk</dc:creator>
 <guid isPermaLink="false">comment 1215748 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/webmasters-corner/march-php-month-bugs-back-your-sites#comment-1215734</link>
    <description> &lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;p&gt;&lt;strong&gt;andy206uk;215730 wrote:&lt;/strong&gt; I have to say, the way he&#039;s handling this is wrong. What he should have done is told the guys that make PHP about the bugs a month in advance and told them that if they didn&#039;t resolve them by a certain deadline THEN he would begin releasing them.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;That&#039;s basically what he&#039;s doing.  The Month of PHP Bugs was announced at least a month ago.  He resigned from the PHP Security Response Team in early December.  He founded the SRT in 2004.&lt;/p&gt;
&lt;p&gt;So the PHP security people were well aware of a lot of unresolved bugs for a long time, as Esser and others had been reporting them for years.  But the team refuse even to acknowledge many of the bugs, let alone attempt to fix them or actually fix them properly.&lt;/p&gt;
&lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;p&gt;&lt;strong&gt;andy206uk;215730 wrote:&lt;/strong&gt; Why should we all suffer because he&#039;s got beef with the PHP team? &lt;img src=&quot;https://www.webmaster-forums.net/misc/smileys/sad.png&quot; title=&quot;Sad&quot; alt=&quot;Sad&quot; class=&quot;smiley-content&quot; /&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;His premise is that we&#039;re already suffering because the PHP team aren&#039;t doing their job.  Hopefully what he&#039;s trying now -- after all his prior effort -- will help improve the situation.&lt;/p&gt;
&lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;p&gt;&lt;strong&gt;pr0gr4mm3r wrote:&lt;/strong&gt; His actions seem quite immature IMHO.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;It may seem so when seen out of context.  You have to bear in mind that he has been dealing with the PHP folks for years and it led nowhere.&lt;/p&gt;
&lt;p&gt;I guess it would be better if he also released patches along with the bugs, but I think that would be an unreasonable ask.  That&#039;s what the PHP security team is there for, after all.&lt;/p&gt;
&lt;p&gt;Anyway, I&#039;m glad this is finally happening.  In my opinion, PHP has been resting on its laurels somewhat in the last couple of years -- not just in security.  I hope the Month of Bugs will either drive the project to refocus, or drive its users to better technologies.&lt;/p&gt;
&lt;p&gt;I can&#039;t imagine that it will have a significant adverse effect for users, though.  The security risks of poorly written PHP applications, or improper server configuration, are far greater than those of bugs in PHP core -- by Esser&#039;s own admission.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://www.webmaster-forums.net/misc/smileys/smile.png&quot; title=&quot;Smiling&quot; alt=&quot;Smiling&quot; class=&quot;smiley-content&quot; /&gt;&lt;/p&gt;
 </description>
     <pubDate>Sat, 24 Feb 2007 13:52:15 +0000</pubDate>
 <dc:creator>Abhishek Reddy</dc:creator>
 <guid isPermaLink="false">comment 1215734 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/webmasters-corner/march-php-month-bugs-back-your-sites#comment-1215733</link>
    <description> &lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;p&gt;Quote: Why should we all suffer because he&#039;s got beef with the PHP team? &lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;His actions seem quite immature IMHO.&lt;/p&gt;
 </description>
     <pubDate>Sat, 24 Feb 2007 13:06:32 +0000</pubDate>
 <dc:creator>pr0gr4mm3r</dc:creator>
 <guid isPermaLink="false">comment 1215733 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/webmasters-corner/march-php-month-bugs-back-your-sites#comment-1215730</link>
    <description> &lt;p&gt;Thanks for pointing this out... I&#039;ve told the sysadmins at the company they work for.&lt;/p&gt;
&lt;p&gt;I have to say, the way he&#039;s handling this is wrong. What he should have done is told the guys that make PHP about the bugs a month in advance and told them that if they didn&#039;t resolve them by a certain deadline THEN he would begin releasing them.&lt;/p&gt;
&lt;p&gt;Why should we all suffer because he&#039;s got beef with the PHP team? &lt;img src=&quot;https://www.webmaster-forums.net/misc/smileys/sad.png&quot; title=&quot;Sad&quot; alt=&quot;Sad&quot; class=&quot;smiley-content&quot; /&gt;&lt;/p&gt;
 </description>
     <pubDate>Sat, 24 Feb 2007 12:41:47 +0000</pubDate>
 <dc:creator>andy206uk</dc:creator>
 <guid isPermaLink="false">comment 1215730 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/webmasters-corner/march-php-month-bugs-back-your-sites#comment-1215715</link>
    <description> &lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;p&gt;Quote: Nobody uses automated backups? Mine are backed up every night.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;We have mostly automatic updates, just have to run a script and enter SSH passwords. Unfortunately our server doesn&#039;t support using certificates for automatic logins. &lt;img src=&quot;https://www.webmaster-forums.net/misc/smileys/sad.png&quot; title=&quot;Sad&quot; alt=&quot;Sad&quot; class=&quot;smiley-content&quot; /&gt;&lt;/p&gt;
&lt;p&gt;I can imagine there will be many bloggers and small businesses which don&#039;t bother backing-up.&lt;/p&gt;
 </description>
     <pubDate>Sat, 24 Feb 2007 07:25:00 +0000</pubDate>
 <dc:creator>JeevesBond</dc:creator>
 <guid isPermaLink="false">comment 1215715 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/webmasters-corner/march-php-month-bugs-back-your-sites#comment-1215710</link>
    <description> &lt;p&gt;I have peace of mind when I do backups myself... but still, I hate bugs...&lt;/p&gt;
 </description>
     <pubDate>Sat, 24 Feb 2007 05:44:08 +0000</pubDate>
 <dc:creator>demonhale</dc:creator>
 <guid isPermaLink="false">comment 1215710 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/webmasters-corner/march-php-month-bugs-back-your-sites#comment-1215700</link>
    <description> &lt;p&gt;Nobody uses automated backups?  Mine are backed up every night.&lt;/p&gt;
 </description>
     <pubDate>Fri, 23 Feb 2007 21:15:43 +0000</pubDate>
 <dc:creator>pr0gr4mm3r</dc:creator>
 <guid isPermaLink="false">comment 1215700 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/webmasters-corner/march-php-month-bugs-back-your-sites#comment-1215592</link>
    <description> &lt;p&gt;Dang! Another busy series of months again then... I hope they just keep it under wraps...&lt;/p&gt;
 </description>
     <pubDate>Wed, 21 Feb 2007 21:39:33 +0000</pubDate>
 <dc:creator>demonhale</dc:creator>
 <guid isPermaLink="false">comment 1215592 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/webmasters-corner/march-php-month-bugs-back-your-sites#comment-1215552</link>
    <description> &lt;p&gt;I&#039;m moving this to Webmaster&#039;s Corner where more people will see it - too important to be left in server-side scripting &lt;img src=&quot;https://www.webmaster-forums.net/misc/smileys/wink.png&quot; title=&quot;Wink&quot; alt=&quot;Wink&quot; class=&quot;smiley-content&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This means that you need to BACK UP anything you have running on php and keep an eye out for upgrades on any scripts you are using.&lt;/p&gt;
 </description>
     <pubDate>Wed, 21 Feb 2007 13:55:58 +0000</pubDate>
 <dc:creator>Megan</dc:creator>
 <guid isPermaLink="false">comment 1215552 at https://www.webmaster-forums.net</guid>
  </item>
  </channel>
</rss>
