in reply to Re^4: Perl::Minimal -- the good, bad, and the ugly...
in thread Perl::Minimal -- the good, bad, and the ugly...

Honestly. In my experience, it's pretty difficult to feel confident that you can safely expose PHP in the wild.

...

I should probably note; I'm speaking largely from a Service Provider standpoint.

Interesting you say that. A few years ago, I was commenting on how few hosting services allow Perl while PHP was nearly ubiquitous. The co-worker I was chatting claimed that Perl is too powerful and assumes the coder knows what she/he is doing, while PHP assumes the coder is an idiot. Therefore, hosting services are much more comfortable with PHP than with Perl.

  • Comment on Re^5: Perl::Minimal -- the good, bad, and the ugly...

Replies are listed 'Best First'.
Re^6: Perl::Minimal -- the good, bad, and the ugly...
by taint (Chaplain) on May 31, 2014 at 02:58 UTC
    WOOT! That's rich.

    I really don't want to take this off topic. But I'll say this much. I can tell you at any given point in time, which (PHP) apps are vulnerable, as my logs are flooded with the name of the vulnerable file name. w/o fail, they all end in .php. On the flip side; I never see a Perl extension, nor any Perl application I am familiar with -- ever.

    In the end; I'll happily grant Perl access, over PHP, any day.

    END PHP vs Perl thread.

    --Chris

    ¡λɐp ʇɑəɹ⅁ ɐ əʌɐɥ puɐ ʻꜱdləɥ ꜱᴉɥʇ ədoH

      On the flip side; I never see a Perl extension, nor any Perl application I am familiar with -- ever.

      I wouldn't get too carried away with the "Perl is more secure than PHP" rhetoric. We've had our own problems too. Like, you know, I don't suppose anyone here really wants to talk about suidperl.

        Ugh. Really? Sure. I'll bring it up. That was what, 5.8? OK. Ya got me. One possible issue, what, some 10 years ago?

        Sheesh. Now I know we're done with this subject.

        P.S. You do that hasn't been an option since ~5.8. Right?

        ¡λɐp ʇɑəɹ⅁ ɐ əʌɐɥ puɐ ʻꜱdləɥ ꜱᴉɥʇ ədoH

      "Ever"? Matt's Scripts were famous for them. I've seen a number of SQL injection attacks in Perl scripts as well.

        Sure. But again. How many years ago? :P

        --Chris

        ¡λɐp ʇɑəɹ⅁ ɐ əʌɐɥ puɐ ʻꜱdləɥ ꜱᴉɥʇ ədoH