in reply to Re^5: Perl::Minimal -- the good, bad, and the ugly...
in thread Perl::Minimal -- the good, bad, and the ugly...

WOOT! That's rich.

I really don't want to take this off topic. But I'll say this much. I can tell you at any given point in time, which (PHP) apps are vulnerable, as my logs are flooded with the name of the vulnerable file name. w/o fail, they all end in .php. On the flip side; I never see a Perl extension, nor any Perl application I am familiar with -- ever.

In the end; I'll happily grant Perl access, over PHP, any day.

END PHP vs Perl thread.

--Chris

¡λɐp ʇɑəɹ⅁ ɐ əʌɐɥ puɐ ʻꜱdləɥ ꜱᴉɥʇ ədoH

  • Comment on Re^6: Perl::Minimal -- the good, bad, and the ugly...

Replies are listed 'Best First'.
Re^7: Perl::Minimal -- the good, bad, and the ugly...
by Anonymous Monk on Jun 03, 2014 at 04:41 UTC

    On the flip side; I never see a Perl extension, nor any Perl application I am familiar with -- ever.

    I wouldn't get too carried away with the "Perl is more secure than PHP" rhetoric. We've had our own problems too. Like, you know, I don't suppose anyone here really wants to talk about suidperl.

      Ugh. Really? Sure. I'll bring it up. That was what, 5.8? OK. Ya got me. One possible issue, what, some 10 years ago?

      Sheesh. Now I know we're done with this subject.

      P.S. You do that hasn't been an option since ~5.8. Right?

      ¡λɐp ʇɑəɹ⅁ ɐ əʌɐɥ puɐ ʻꜱdləɥ ꜱᴉɥʇ ədoH

Re^7: Perl::Minimal -- the good, bad, and the ugly...
by astroboy (Chaplain) on Jun 05, 2014 at 00:43 UTC
    "Ever"? Matt's Scripts were famous for them. I've seen a number of SQL injection attacks in Perl scripts as well.

      Sure. But again. How many years ago? :P

      --Chris

      ¡λɐp ʇɑəɹ⅁ ɐ əʌɐɥ puɐ ʻꜱdləɥ ꜱᴉɥʇ ədoH

        I have yet to start a job that did not have glaring security holes in their web-facing Perl code. Web security is overwhelmingly a function of the hacker and only slightly afforded by safety nets and proper buffer checks and such in the binary/compiled code that’s running. Nearly every single newbie SQL question posted here is absent placeholders. And that’s just the most obvious example of pervasive security ignorance.