Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:29619 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 65134 invoked by uid 1010); 21 May 2007 13:27:32 -0000 Delivered-To: ezmlm-scan-internals@lists.php.net Delivered-To: ezmlm-internals@lists.php.net Received: (qmail 65119 invoked from network); 21 May 2007 13:27:32 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 21 May 2007 13:27:32 -0000 Authentication-Results: pb1.pair.com smtp.mail=lists@block-online.eu; spf=permerror; sender-id=unknown Authentication-Results: pb1.pair.com header.from=lists@block-online.eu; sender-id=unknown Received-SPF: error (pb1.pair.com: domain block-online.eu from 81.169.146.160 cause and error) X-PHP-List-Original-Sender: lists@block-online.eu X-Host-Fingerprint: 81.169.146.160 mo-p00-ob.rzone.de Solaris 10 (beta) Received: from [81.169.146.160] ([81.169.146.160:31993] helo=mo-p00-ob.rzone.de) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id C2/96-03101-24E91564 for ; Mon, 21 May 2007 09:27:31 -0400 Received: from ollie.block.home (dslb-084-063-176-161.pools.arcor-ip.net [84.63.176.161]) by post.webmailer.de (fruni mo50) (RZmta 6.5) with ESMTP id B02627j4LBqDOR ; Mon, 21 May 2007 15:27:27 +0200 (MEST) To: internals@lists.php.net Date: Mon, 21 May 2007 15:25:59 +0200 User-Agent: KMail/1.7.1 References: <465022BE.1020905@hardened-php.net> In-Reply-To: <465022BE.1020905@hardened-php.net> Cc: Stefan Esser MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-15" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-ID: <200705211525.59932.lists@block-online.eu> X-RZG-AUTH: jsAgD75E4FZRsMYse5W8COLJ40bV42cELvihCND/Uu2brXmKBiVnjTTHjmWT X-RZG-CLASS-ID: mo00 Subject: Re: [PHP-DEV] Dismantling the lies... From: lists@block-online.eu (Oliver Block) Am Sonntag, 20. Mai 2007 12:28 schrieb Stefan Esser: > it is no secret that I am really sick and tired of this constant stream > of nonsense and > lies comming out of the mouths of PHP developers when it comes to > security issues. What I do not understand than is, why are you doing all this? You are searching the source code for unsecure usage of C to uncover it. What drives you? Another thing: I remember that Zev wrote that it is not a goal yet of the php group to be safe against local attackers. That is a clear statement. Let me also say that your "style of writing" does not make it pleasant to read your postings. > Xdebug, Suhosin, Hardening Patch How is the acceptance of the Hardening Patch? Regards, Oliver